Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in the libtiff library. A signed integer overflow exists in the putcontig8bitYCbCr44tile function (and potentially similar functions like putcontig8bitYCbCr42tile, putcontig8bitYCbCr22tile, and putcontig8bitYCbCr12tile) within tif_getimage.c. When processing a specially crafted TIFF file with an extremely large width and specific YCbCr subsampling, the calculation for the pointer progression variable (incr) can overflow the 32-bit signed integer boundary. This results in an incorrect negative progression of memory pointers, leading to an out-of-bounds heap write. An attacker could exploit this to cause a denial of service (application crash) or potentially execute arbitrary code.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:12265 https://access.redhat.com/errata/RHSA-2026:12265
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:12271 https://access.redhat.com/errata/RHSA-2026:12271
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:14929 https://access.redhat.com/errata/RHSA-2026:14929
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:16055 https://access.redhat.com/errata/RHSA-2026:16055
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19150 https://access.redhat.com/errata/RHSA-2026:19150
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19363 https://access.redhat.com/errata/RHSA-2026:19363
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:19586 https://access.redhat.com/errata/RHSA-2026:19586
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:19585 https://access.redhat.com/errata/RHSA-2026:19585
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:19604 https://access.redhat.com/errata/RHSA-2026:19604
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:19608 https://access.redhat.com/errata/RHSA-2026:19608
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:19609 https://access.redhat.com/errata/RHSA-2026:19609
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:19659 https://access.redhat.com/errata/RHSA-2026:19659
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:19657 https://access.redhat.com/errata/RHSA-2026:19657
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:19702 https://access.redhat.com/errata/RHSA-2026:19702
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:20583 https://access.redhat.com/errata/RHSA-2026:20583
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:20591 https://access.redhat.com/errata/RHSA-2026:20591
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:20592 https://access.redhat.com/errata/RHSA-2026:20592
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:20585 https://access.redhat.com/errata/RHSA-2026:20585
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:24992 https://access.redhat.com/errata/RHSA-2026:24992
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:25910 https://access.redhat.com/errata/RHSA-2026:25910