A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption. | |
| Title | Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough | |
| First Time appeared |
Redhat
Redhat ceph Storage Redhat enterprise Linux Redhat hummingbird |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:/a:redhat:ceph_storage:4 cpe:/a:redhat:ceph_storage:6 cpe:/a:redhat:ceph_storage:7 cpe:/a:redhat:ceph_storage:8 cpe:/a:redhat:ceph_storage:9 cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat ceph Storage Redhat enterprise Linux Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-11T17:56:57.498Z
Reserved: 2026-07-31T15:34:43.453Z
Link: CVE-2026-18495
No data.
Status : Received
Published: 2026-09-11T18:16:56.690
Modified: 2026-09-11T18:16:56.690
Link: CVE-2026-18495
No data.
OpenCVE Enrichment
No data.
Weaknesses