{"id":"AZL-97923","summary":"CVE-2026-52492 affecting package libtiff 4.6.0-14","details":"An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image","modified":"2026-09-08T05:27:28Z","published":"2026-08-24T21:17:19Z","upstream":["CVE-2026-52492"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52492"}],"affected":[{"package":{"name":"libtiff","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libtiff"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.6.0-14"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97923.json"}}],"schema_version":"1.9.0"}