Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:41892: Important: libtiff security, bug fix, and enhancement update

This update addresses two high-severity vulnerabilities in libtiff: CVE-2023-52355 (CVSS 7.5), a denial-of-service issue via memory exhaustion, and CVE-2026-12912 (CVSS 7.3), a heap-based buffer overflow triggered by a crafted PixarLog-compressed TIFF image. The NVD data indicates libtiff versions prior to 4.6.0 are affected by CVE-2023-52355. Red Hat Enterprise Linux 10 systems should apply the provided libtiff update package immediately.
Read Full Article →

Red Hat Product Errata RHSA-2026:41892 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:41892 - Security Advisory Overview Updated Packages Synopsis Important: libtiff security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libtiff is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM (CVE-2023-52355) libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) Bug Fix(es) and Enhancement(s): Reintroduce the `tiffcp -i` option (JIRA:RHEL-185328) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2251326 - CVE-2023-52355 libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM BZ - 2492871 - CVE-2026-12912 libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image CVEs CVE-2023-52355 CVE-2026-12912 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM libtiff-4.6.0-8.el10_2.4.src.rpm SHA-256: dd697bfe9933289b203f558a7a11fa2dacc9ecd43cf0d235c014cc0548db7771 x86_64 libtiff-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: ea1504c08dbff82862829bef196d841778b7731414688e51ff9844674b8410bd libtiff-debuginfo-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: 411afbd7c89d678b07c1f7af34a2ef19b7bb8b1ecc4b71789d7c3a8de53c9188 libtiff-debugsource-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: a14406267439e6c74f707559f81e39efcd84e8b90096e3ba83e6f6800df60030 libtiff-devel-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: 21cd62ac0380ebcb96f5b31f5edf9a8f79fd9f38b8ba2dac37568ac062cf2087 libtiff-tools-debuginfo-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: 828639ec4c0264e031bcee8065d22b4fa6692318d75e049a4658948f54a7f82d Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM libtiff-4.6.0-8.el10_2.4.src.rpm SHA-256: dd697bfe9933289b203f558a7a11fa2dacc9ecd43cf0d235c014cc0548db7771 x86_64 libtiff-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: ea1504c08dbff82862829bef196d841778b7731414688e51ff9844674b8410bd libtiff-debuginfo-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: 411afbd7c89d678b07c1f7af34a2ef19b7bb8b1ecc4b71789d7c3a8de53c9188 libtiff-debugsource-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: a14406267439e6c74f707559f81e39efcd84e8b90096e3ba83e6f6800df60030 libtiff-devel-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: 21cd62ac0380ebcb96f5b31f5edf9a8f79fd9f38b8ba2dac37568ac062cf2087 libtiff-tools-debuginfo-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: 828639ec4c0264e031bcee8065d22b4fa6692318d75e049a4658948f54a7f82d Red Hat Enterprise Linux for IBM z Systems 10 SRPM libtiff-4.6.0-8.el10_2.4.src.rpm SHA-256: dd697bfe9933289b203f558a7a11fa2dacc9ecd43cf0d235c014cc0548db7771 s390x libtiff-4.6.0-8.el10_2.4.s390x.rpm SHA-256: 0fd5766c2f4a997bf70c023c4287e3ab3d1b172471b4d162701d6579e4ee410e libtiff-debuginfo-4.6.0-8.el10_2.4.s390x.rpm SHA-256: a528ed6b6c1d53bf728af6175045e9f920bae127da7883019ca5d365937c7f26 libtiff-debugsource-4.6.0-8.el10_2.4.s390x.rpm SHA-256: 00a5b029a300def005773626fedba50564b8462d21b306e0c7c873fc836054b1 libtiff-devel-4.6.0-8.el10_2.4.s390x.rpm SHA-256: d80a5d1ddecda645525c24cff2eeb1596191575e270175cdc26df5a7b9ba33f8 libtiff-tools-debuginfo-4.6.0-8.el10_2.4.s390x.rpm SHA-256: 4f772b9c1a375bf5463fe5470fea419998feaf9501aac928c05ff4d187d17ca3 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM libtiff-4.6.0-8.el10_2.4.src.rpm SHA-256: dd697bfe9933289b203f558a7a11fa2dacc9ecd43cf0d235c014cc0548db7771 s390x libtiff-4.6.0-8.el10_2.4.s390x.rpm SHA-256: 0fd5766c2f4a997bf70c023c4287e3ab3d1b172471b4d162701d6579e4ee410e libtiff-debuginfo-4.6.0-8.el10_2.4.s390x.rpm SHA-256: a528ed6b6c1d53bf728af6175045e9f920bae127da7883019ca5d365937c7f26 libtiff-debugsource-4.6.0-8.el10_2.4.s390x.rpm SHA-256: 00a5b029a300def005773626fedba50564b8462d21b306e0c7c873fc836054b1 libtiff-devel-4.6.0-8.el10_2.4.s390x.rpm SHA-256: d80a5d1ddecda645525c24cff2eeb1596191575e270175cdc26df5a7b9ba33f8 libtiff-tools-debuginfo-4.6.0-8.el10_2.4.s390x.rpm SHA-256: 4f772b9c1a375bf5463fe5470fea419998feaf9501aac928c05ff4d187d17ca3 Red Hat Enterprise Linux for Power, little endian 10 SRPM libtiff-4.6.0-8.el10_2.4.src.rpm SHA-256: dd697bfe9933289b203f558a7a11fa2dacc9ecd43cf0d235c014cc0548db7771 ppc64le libtiff-4.6.0-8.el10_2.4.ppc64le.rpm SHA-256: f0c13f86c5789362e9ed72bafa592a3567b542b16360893c39ad382ccec0e492 libtiff-debuginfo-4.6.0-8.el10_2.4.ppc64le.rpm SHA-256: e54c95ebfb9de4515237c7b4053b8130a4aff6a0a9ac2ca7ffdb122fc26cb750 libtiff-debugsource-4.6.0-8.el10_2.4.ppc64le.rpm SHA-256: 1c060b34d13d4ca3cc90fa9ef113cf44154c356e2438e706ec5e3196df8f3184 libtiff-devel-4.6.0-8.el10_2.4.ppc64le.rpm SHA-256: 2b6ad54d3171e092b868a6a2a5cb61fb2491d388752115b0b9fbdfbeb1d90677 libtiff-tools-debuginfo-4.6.0-8.el10_2.4.ppc64le.rpm SHA-256: f3bae3a8fd6a12f98d2692dc59e51d5567a91bb00a8e8af432ece38113ff765a Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM libtiff-4.6.0-8.el10_2.4.src.rpm SHA-256: dd697bfe9933289b203f558a7a11fa2dacc9ecd43cf0d235c014cc0548db7771 ppc64le libtiff-4.6.0-8.el10_2.4.ppc64le.rpm SHA-256: f0c13f86c5789362e9ed72bafa592a3567b542b16360893c39ad382ccec0e492 libtiff-debuginfo-4.6.0-8.el10_2.4.ppc64le.rpm SHA-256: e54c95ebfb9de4515237c7b4053b8130a4aff6a0a9ac2ca7ffdb122fc26cb750 libtiff-debugsource-4.6.0-8.el10_2.4.ppc64le.rpm SHA-256: 1c060b34d13d4ca3cc90fa9ef113cf44154c356e2438e706ec5e3196df8f3184 libtiff-devel-4.6.0-8.el10_2.4.ppc64le.rpm SHA-256: 2b6ad54d3171e092b868a6a2a5cb61fb2491d388752115b0b9fbdfbeb1d90677 libtiff-tools-debuginfo-4.6.0-8.el10_2.4.ppc64le.rpm SHA-256: f3bae3a8fd6a12f98d2692dc59e51d5567a91bb00a8e8af432ece38113ff765a Red Hat Enterprise Linux for ARM 64 10 SRPM libtiff-4.6.0-8.el10_2.4.src.rpm SHA-256: dd697bfe9933289b203f558a7a11fa2dacc9ecd43cf0d235c014cc0548db7771 aarch64 libtiff-4.6.0-8.el10_2.4.aarch64.rpm SHA-256: 0996e0e11694797ca821f1147788d6d2441c79d37a79fe10fb49f96d662e51e8 libtiff-debuginfo-4.6.0-8.el10_2.4.aarch64.rpm SHA-256: d677b7c8a515e1993b1d53b49671d0a00d077274ab9e9f74428436dac1f3aee7 libtiff-debugsource-4.6.0-8.el10_2.4.aarch64.rpm SHA-256: 851c0f50a9fed3f33b916972b4119af66a6a8fde574f86ed87d82f634a909bb2 libtiff-devel-4.6.0-8.el10_2.4.aarch64.rpm SHA-256: e8cf0e8e51a73f615f7205513caea533b777ddc20830ef584439a2b23522a525 libtiff-tools-debuginfo-4.6.0-8.el10_2.4.aarch64.rpm SHA-256: d726a2145239d85137a591052f248adcc02b0ecd49784aec3573d66066c60206 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM libtiff-4.6.0-8.el10_2.4.src.rpm SHA-256: dd697bfe9933289b203f558a7a11fa2dacc9ecd43cf0d235c014cc0548db7771 aarch64 libtiff-4.6.0-8.el10_2.4.aarch64.rpm SHA-256: 0996e0e11694797ca821f1147788d6d2441c79d37a79fe10fb49f96d662e51e8 libtiff-debuginfo-4.6.0-8.el10_2.4.aarch64.rpm SHA-256: d677b7c8a515e1993b1d53b49671d0a00d077274ab9e9f74428436dac1f3aee7 libtiff-debugsource-4.6.0-8.el10_2.4.aarch64.rpm SHA-256: 851c0f50a9fed3f33b916972b4119af66a6a8fde574f86ed87d82f634a909bb2 libtiff-devel-4.6.0-8.el10_2.4.aarch64.rpm SHA-256: e8cf0e8e51a73f615f7205513caea533b777ddc20830ef584439a2b23522a525 libtiff-tools-debuginfo-4.6.0-8.el10_2.4.aarch64.rpm SHA-256: d726a2145239d85137a591052f248adcc02b0ecd49784aec3573d66066c60206 Red Hat CodeReady Linux Builder for x86_64 10 SRPM x86_64 libtiff-debuginfo-4.6.0-8.el10_2.4.x86_64.rpm SHA-256: 411afbd7c89d678b07c1f7af34a2ef19b7bb

Share this article