CVE-2026-52492

EUVD-2026-65145
An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.68%
Debian logo
Debian Releases
Debian Product
Codename
tiff
bookworm
unimportant
bookworm (security)
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
trixie (security)
unimportant
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libtiff
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
libtiff-debuginfo
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
libtiff-devel
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
libtiff-static
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
libtiff-tools
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed