CVE-2025-61145

libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*

History

24 Feb 2026, 20:17

Type Values Removed Values Added
First Time Libtiff
Libtiff libtiff
CPE cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.0
Summary
  • (es) Se descubrió que libtiff hasta la v4.7.1 contenía una doble liberación a través del componente tools/tiffcrop.c.
CWE CWE-415
References () https://gist.github.com/optionGo/062f109569196dbffd8ac12020b42289 - () https://gist.github.com/optionGo/062f109569196dbffd8ac12020b42289 - Third Party Advisory
References () https://gitlab.com/libtiff/libtiff/-/issues/736 - () https://gitlab.com/libtiff/libtiff/-/issues/736 - Exploit, Issue Tracking
References () https://gitlab.com/libtiff/libtiff/-/merge_requests/753 - () https://gitlab.com/libtiff/libtiff/-/merge_requests/753 - Issue Tracking

23 Feb 2026, 19:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 19:22

Updated : 2026-02-25 15:20


NVD link : CVE-2025-61145

Mitre link : CVE-2025-61145

CVE.ORG link : CVE-2025-61145


JSON object : View

Products Affected

libtiff

  • libtiff
CWE
CWE-415

Double Free