{"id":"ROOT-OS-DEBIAN-13-CVE-2026-36849","summary":"CVE-2026-36849 in tiff - Patched by Root","details":"Root has patched CVE-2026-36849 in the tiff package for Root:Debian:13. Multiple fixed versions available.","modified":"2026-09-03T09:15:02.071701337Z","published":"2026-09-03T07:42:25Z","upstream":["CVE-2026-36849"],"database_specific":{"source":"Root","distro":"debian","distro_version":"13","severity":"HIGH"},"affected":[{"package":{"name":"tiff","ecosystem":"Root:Debian:13"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.0-3+deb13u3.aikido.8"},{"fixed":"4.7.0-3+deb13u3.aikido.9"},{"fixed":"4.7.0-3+deb13u3.aikido.10"}]}],"database_specific":{"root_patched":true,"total_fixed_versions":3,"upstream_version":"4.7.0-3+deb13u3","all_fixed_versions":["4.7.0-3+deb13u3.aikido.8","4.7.0-3+deb13u3.aikido.9","4.7.0-3+deb13u3.aikido.10"],"source":"https://api.root.io/external/osv/ROOT-OS-DEBIAN-13-CVE-2026-36849.json","root_patch_version":"aikido.10"}},{"package":{"name":"rootio-tiff","ecosystem":"Root:Debian:13"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.0-3+deb13u3.aikido.8"},{"fixed":"4.7.0-3+deb13u3.aikido.9"},{"fixed":"4.7.0-3+deb13u3.aikido.10"}]}],"database_specific":{"source":"https://api.root.io/external/osv/ROOT-OS-DEBIAN-13-CVE-2026-36849.json","all_fixed_versions":["4.7.0-3+deb13u3.aikido.8","4.7.0-3+deb13u3.aikido.9","4.7.0-3+deb13u3.aikido.10"],"root_patch_version":"aikido.10","root_patched":true,"total_fixed_versions":3,"upstream_version":"4.7.0-3+deb13u3"}}],"schema_version":"1.9.0"}