CVE-2026-4775

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libtiff:libtiff:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

21 Apr 2026, 16:34

Type Values Removed Values Added
First Time Redhat
Redhat enterprise Linux
Libtiff
Debian debian Linux
Redhat hardened Images
Debian
Libtiff libtiff
CPE cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:libtiff:libtiff:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2026-4775 - () https://access.redhat.com/security/cve/CVE-2026-4775 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2450768 - () https://bugzilla.redhat.com/show_bug.cgi?id=2450768 - Issue Tracking, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2026/04/msg00016.html - () https://lists.debian.org/debian-lts-announce/2026/04/msg00016.html - Mailing List, Third Party Advisory

17 Apr 2026, 17:17

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2026/04/msg00016.html -
Summary
  • (es) Se encontró un fallo en la biblioteca libtiff. Un atacante remoto podría explotar una vulnerabilidad de desbordamiento de entero con signo en la función putcontig8bitYCbCr44tile al proporcionar un archivo TIFF especialmente diseñado. Este fallo puede llevar a una escritura fuera de límites en el heap debido a cálculos incorrectos del puntero de memoria, potencialmente causando una denegación de servicio (caída de la aplicación) o ejecución de código arbitrario.

24 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 15:16

Updated : 2026-04-21 16:34


NVD link : CVE-2026-4775

Mitre link : CVE-2026-4775

CVE.ORG link : CVE-2026-4775


JSON object : View

Products Affected

libtiff

  • libtiff

debian

  • debian_linux

redhat

  • enterprise_linux
  • hardened_images
CWE
CWE-190

Integer Overflow or Wraparound