https://seclists.org/oss-sec/2026/q2/952: [CVE-2026-36849] libtiff: Denial of Service via large SamplesPerPixel tag
Published Jun 17, 2026
·Updated
Affected Software
1 affected component
LibTIFF libtiff<=4.7.1
Frequently Asked Questions
1
What is the severity of CVE-2026-36849?
CVE-2026-36849 is classified as a denial of service vulnerability.
2
How do I fix CVE-2026-36849?
To mitigate CVE-2026-36849, update libtiff to version 4.7.2 or later.
3
What versions are affected by CVE-2026-36849?
CVE-2026-36849 affects libtiff version 4.7.1 and earlier.
4
What type of attack does CVE-2026-36849 involve?
CVE-2026-36849 involves a denial of service attack through crafted TIFF files.
5
Can CVE-2026-36849 lead to data loss?
CVE-2026-36849 does not lead to data loss but may make the service unavailable.