CVE-2026-12912
HIGH SEVERITYCVSS Score & Metrics
Base Score
7.3 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Description
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-122
Source
NVD
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images
External References
- https://access.redhat.com/security/cve/CVE-2026-12912
- https://bugzilla.redhat.com/show_bug.cgi?id=2492871
- https://gitlab.com/libtiff/libtiff/-/merge_requests/873
- https://gitlab.com/libtiff/libtiff/-/work_items/824
- https://access.redhat.com/security/cve/CVE-2026-12912
- https://bugzilla.redhat.com/show_bug.cgi?id=2492871
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12912.json
Discussion (0)
Add Comment
No comments yet. Be the first!