Issued at: 2025-10-10
Updated at: 2025-10-15
Synopsis
Important: compat-libtiff3 security update
Description
The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.
Security Fix(es):
* libtiff: Libtiff Write-What-Where (CVE-2025-9900)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected products
Rocky Linux 8 aarch64
Rocky Linux 8 x86_64
Fixes
2392784
CVEs
CVE-2025-9900
Affected packages
Rocky Linux 8 aarch64 - AppStream
compat-libtiff3-0:3.9.4-14.el8_10.aarch64.rpm
compat-libtiff3-0:3.9.4-14.el8_10.src.rpm
compat-libtiff3-debuginfo-0:3.9.4-14.el8_10.aarch64.rpm
compat-libtiff3-debugsource-0:3.9.4-14.el8_10.aarch64.rpm
Rocky Linux 8 x86_64 - AppStream
compat-libtiff3-0:3.9.4-14.el8_10.i686.rpm
compat-libtiff3-0:3.9.4-14.el8_10.src.rpm
compat-libtiff3-0:3.9.4-14.el8_10.x86_64.rpm
compat-libtiff3-debuginfo-0:3.9.4-14.el8_10.i686.rpm
compat-libtiff3-debuginfo-0:3.9.4-14.el8_10.x86_64.rpm
compat-libtiff3-debugsource-0:3.9.4-14.el8_10.i686.rpm
compat-libtiff3-debugsource-0:3.9.4-14.el8_10.x86_64.rpm