{"id":"AZL-101736","summary":"CVE-2026-18495 affecting package libtiff 4.6.0-14","details":"A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.","modified":"2026-09-18T05:37:08Z","published":"2026-09-11T18:16:56Z","upstream":["CVE-2026-18495"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18495"}],"affected":[{"package":{"name":"libtiff","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libtiff"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.6.0-14"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101736.json"}}],"schema_version":"1.9.0"}