In libtiff's tiffcrop utility, a uint32_t underflow results in an out-of-bounds read and write in extractContigSamples8bits and extractContigSamplesShifted32bits of tiffcrop.c. References: https://gitlab.com/libtiff/libtiff/-/issues/350 https://gitlab.com/libtiff/libtiff/-/issues/351 https://gitlab.com/libtiff/libtiff/-/merge_requests/294/diffs?commit_id=7d7bfa4416366ec64068ac389414241ed4730a54
Created iv tracking bugs for this issue: Affects: fedora-35 [bug 2118851] Affects: fedora-36 [bug 2118853] Created libtiff tracking bugs for this issue: Affects: fedora-35 [bug 2118850] Affects: fedora-36 [bug 2118854] Created mingw-libtiff tracking bugs for this issue: Affects: fedora-35 [bug 2118852] Affects: fedora-36 [bug 2118855]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:0095 https://access.redhat.com/errata/RHSA-2023:0095
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-2867