Issued at: 2026-07-22
Updated at: 2026-07-23
Synopsis
Important: libtiff security, bug fix, and enhancement update
Description
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.
Security Fix(es):
* libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM (CVE-2023-52355)
* libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912)
Bug Fix(es) and Enhancement(s):
* Reintroduce the `tiffcp -i` option (JIRA:Rocky Linux-185328)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.