Bug 2531414 (CVE-2026-18495)

Summary: CVE-2026-18495 libtiff: libtiff: heap-buffer overflow via numeric truncation in the JPEG raw passthrough
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: amctagga, aoconnor, bniver, flucifre, gmeno, groman, mbenjamin, mhackett, rhel-process-autobot, sostapov, vereddy, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-10 12:33:02 UTC
An AddressSanitizer (ASan)-confirmed heap-buffer overflow exists in the tiff2pdf
utility of libtiff (tested on version 4.5.0). The vulnerability is triggered
during the processing of crafted BigTIFF files, leading to a massive
out-of-bounds memory copy that causes a crash and presents a severe memory
corruption risk.

Technical Details

The root cause is an integer truncation flaw located in the JPEG raw passthrough
path within tools/tiff2pdf.c, specifically in the t2p_readwrite_pdf_image()
function.When parsing BigTIFF files, StripByteCounts values are correctly read
as 64-bit unsigned integers (uint64_t). However, the variable used to track the
maximum strip length—max_striplength—is declared as a 32-bit unsigned integer
(uint32_t). If an attacker provides a crafted BigTIFF file with a
StripByteCounts value exceeding the 32-bit limit, the value is truncated upon
assignment to max_striplength.This truncation results in an undersized heap
allocation. Subsequently, TIFFReadRawStrip(..., -1) attempts to copy the full
64-bit strip byte count into this inadequate buffer, resulting in a heap-based
buffer overflow that can exceed 4GB.

Affected VersionsVulnerable:

libtiff versions 3.9.0 through 4.7.0.

Fixed: libtiff version 4.7.1.

Upstream Status and RemediationUpstream developers have addressed this issue in
version 4.7.1 by changing the data type of max_striplength from uint32_t to
uint64_t.

Note for Downstream Maintainers: The upstream libtiff project policy focuses on
maintaining the current source tree and issuing new releases rather than
backporting patches to legacy versions.

Commit: https://gitlab.com/libtiff/libtiff/-/commit/67fd283d276f09db54dc39b9ef7b979d4b45c4b1Merge
Request (!729): https://gitlab.com/libtiff/libtiff/-/merge_requests/729