Description
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Published: 2026-09-11
Score: 6.1 Medium
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Title Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough
First Time appeared Redhat
Redhat ceph Storage
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-122
CPEs cpe:/a:redhat:ceph_storage:4
cpe:/a:redhat:ceph_storage:6
cpe:/a:redhat:ceph_storage:7
cpe:/a:redhat:ceph_storage:8
cpe:/a:redhat:ceph_storage:9
cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat ceph Storage
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H'}


Subscriptions

Redhat Ceph Storage Enterprise Linux Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-11T17:56:57.498Z

Reserved: 2026-07-31T15:34:43.453Z

Link: CVE-2026-18495

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T18:16:56.690

Modified: 2026-09-11T18:16:56.690

Link: CVE-2026-18495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses