Bug 2483473 (CVE-2026-46599) - CVE-2026-46599 golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
Summary: CVE-2026-46599 golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Se...
Keywords:
Status: NEW
Alias: CVE-2026-46599
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2494477 2494478 2494480 2494481 2494482 2494479
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-29 21:01 UTC by OSIDB Bzimport
Modified: 2026-07-29 19:54 UTC (History)
13 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:48151 0 None None None 2026-07-29 19:54:32 UTC

Description OSIDB Bzimport 2026-05-29 21:01:54 UTC
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.

Comment 4 errata-xmlrpc 2026-07-29 19:54:30 UTC
This issue has been addressed in the following products:

  Cryostat 4 on RHEL 9

Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151


Note You need to log in before you can comment on or make changes to this bug.