{"id":"RLSA-2026:47183","summary":"Important: compat-libtiff3 security update","details":"The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.\n\nSecurity Fix(es):\n\n* libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-08-03T12:30:05.346677411Z","published":"2026-08-03T12:01:09.862125Z","upstream":["CVE-2026-12912"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2026:47183"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492871"}],"affected":[{"package":{"name":"compat-libtiff3","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/compat-libtiff3?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.9.4-16.el8_10"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2026:47183.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}],"credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}