[CLSA-2026:1776349106] libtiff: Fix of 5 CVEs
Type:
security
Severity:
('Moderate', ['ELSCVE-89758', 'ELSCVE-89659', 'ELSCVE-89584', 'ELSCVE-89573', 'ELSCVE-89551'])
Release date:
2026-04-16 14:18:31 UTC
Description:
- CVE-2022-34526: fix stack buffer overflow in _TIFFVGetField via invalid codec-specific tag - CVE-2023-2908: fix null pointer dereference in countInkNamesString in tif_dir.c - CVE-2023-6277: prevent out-of-memory attacks by comparing allocation size with file size - CVE-2023-1916: fix out-of-bounds read in extractImageSection in tiffcrop.c - CVE-2023-3164: fix heap-buffer-overflow in extractImageSection in tiffcrop.c
Updated packages:
  • libtiff-4.4.0-13.el9_6.2.tuxcare.els6.i686.rpm
    sha:fbadc17240f025e9d9547d9510c1f2152a74531b1f9f8b3a29cb4394992675de
  • libtiff-4.4.0-13.el9_6.2.tuxcare.els6.x86_64.rpm
    sha:26c7bf60d50e1a8baf71e075e0468e6cb530093b4043f66282c650b80decc2cb
  • libtiff-devel-4.4.0-13.el9_6.2.tuxcare.els6.i686.rpm
    sha:faab1f24d1ac16f140467fc29ef0ff74b4d1feb6b2b02de8c4c91ef421ab2278
  • libtiff-devel-4.4.0-13.el9_6.2.tuxcare.els6.x86_64.rpm
    sha:8d7deac27161770cf001467721dbc7a23a89613b3171efb2d64877d75f0f8275
  • libtiff-static-4.4.0-13.el9_6.2.tuxcare.els6.x86_64.rpm
    sha:dc0b82063b6316404855d41e8751d8dc65841ff4092564e1a09cd55ab17a4d88
  • libtiff-tools-4.4.0-13.el9_6.2.tuxcare.els6.x86_64.rpm
    sha:59164d7710ea05a901ce19d4dd4a6a1afc55bf43cb4e354271a148f1177d2217
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.