CVE-2026-52490

EUVD-2026-65144
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 41.67%
Debian logo
Debian Releases
Debian Product
Codename
tiff
bookworm
vulnerable
bookworm (security)
vulnerable
forky
4.7.2-1
fixed
sid
4.7.2-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libtiff
RHEL 8
0:4.0.9-39.el8_10
fixed
libtiff-devel
RHEL 8
0:4.0.9-39.el8_10
fixed
libtiff-tools
RHEL 8
0:4.0.9-39.el8_10
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libtiff
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.28
fixed
libtiff-debuginfo
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.28
fixed
libtiff-debugsource
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.28
fixed
libtiff-devel
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.28
fixed
libtiff-static
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.28
fixed
libtiff-tools
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.28
fixed
libtiff-tools-debuginfo
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.28
fixed