{"id":"SUSE-SU-2026:2853-1","summary":"Security update for tiff","details":"This update for tiff fixes the following issues:\n\nUpdate to version 4.7.2.\n\nSecurity issues fixed:\n\n- CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog-compressed TIFF image (bsc#1269779).\n- CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value\n  (bsc#1268434).\n\nOther updates and bugfixes:\n\n- Version 4.7.2:\n  - Software configuration changes:\n    * cmake: Fix bundle identifiers to use reverse-DNS format\n    * cmake: Fix and improve Apple framework build support\n    * cmake: Use TurboJPEG CONFIG by default (issue #767)\n    * cmake: changes related to 8-/12-bit modes\n    * cmake: Replace CMath::CMath with direct link to avoid export.\n    * Support for iOS-derived builds\n    * Simplify cmake byte order version check\n    * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions\n    * configure.ac: Require bootstrap with at least Autoconf 2.71.\n  - Library changes:\n    * New/improved functionalities::\n    + Add TIFFGetMaxCompressionRatio() and use it in _TIFFReadEncoded[Tile|Strip)AndAllocBuffer() (issue #781)\n  - Bug fixes:\n    * Handle negative TIFFReadFile results before state updates (issue #854)\n    * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip\n    * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777)\n    * tif_dirwrite.c: add integer overflow checks to allocation size calculations\n    * tif_print.c: add integer overflow checks to allocation size calculations\n    * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop\n    * DumpModeSeek: add bounds check to prevent OOB pointer advance\n    * TIFFGrowStrips: fix use-after-free on partial realloc failure.\n    * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before\n      accessing it.\n    * TIFFRGBAImage: avoid int overflows in put functions (issue #830)\n    * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792)\n    * tif_getimage: Widen pointer-offset arithmetic in tif_getimage\n    * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798)\n    * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling\n      block to prevent out-of-bounds writes. (issue #753)\n    * TIFFReadRGBAImage(): prevent integer overflow and later heap overflow (issue #787)\n    * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831)\n    * TIFFLinkDirectory() checks for IFD loops (issue #788)\n    * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails.\n    * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805)\n    * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values\n      (https://github.com/OSGeo/gdal/issues/13465)\n    * tif_getimage: reject tile widths that would overflow toskew (issue #808)\n    * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit.\n    * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777).\n    * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode\n      (https://issues.oss-fuzz.com/issues/471328917)\n    * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode\n    * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755).\n    * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749)\n    * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892)\n    * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory\n      disclosure (issue #826)\n    * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773)\n    * JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501)\n    * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow\n    * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850)\n    * PixarLog: error out on invalid ABGR output buffer sizes.\n    * PixarLog: complete ABGR bounds check for multi-row strip decoding.\n    * PixarLog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 (issue #824)\n    * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789).\n    * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797)\n    * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds\n      (https://issues.oss-fuzz.com/issues/506737072)\n    * OJPEG: fix integer overflow in subsampling buffer allocation.\n    * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795).\n    * OJPEG fix potential integer overflow/out-of-bounds access (issue #796).\n    * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b)\n    * fix null pointer deference in issue #782.\n    * fix stack-overflow in issue #784.\n  - Other changes:\n    * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739).\n    * Harden integer size and offset calculations (issue #897)\n    * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication\n    * Move widening casts inside multiplication scope.\n    * Lots of compiler warning fixes related to enabling more warning flags\n    * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773)\n    * TIFFFillStrip(): prevent harmless unsigned integer overflow\n","modified":"2026-07-13T18:24:55.720580465Z","published":"2026-07-10T17:54:44Z","related":["CVE-2026-12912","CVE-2026-36849","CVE-2026-4775"],"upstream":["CVE-2026-12912","CVE-2026-36849","CVE-2026-4775"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262853-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268434"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269779"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12912"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-36849"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4775"}],"affected":[{"package":{"name":"tiff","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.2-150600.3.29.1"}]}],"ecosystem_specific":{"binaries":[{"libtiff6":"4.7.2-150600.3.29.1","libtiff6-32bit":"4.7.2-150600.3.29.1","libtiff-devel":"4.7.2-150600.3.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2853-1.json"}},{"package":{"name":"tiff","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.2-150600.3.29.1"}]}],"ecosystem_specific":{"binaries":[{"tiff":"4.7.2-150600.3.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2853-1.json"}},{"package":{"name":"tiff","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.2-150600.3.29.1"}]}],"ecosystem_specific":{"binaries":[{"libtiff6-32bit":"4.7.2-150600.3.29.1","libtiff-devel":"4.7.2-150600.3.29.1","libtiff6":"4.7.2-150600.3.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2853-1.json"}},{"package":{"name":"tiff","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.2-150600.3.29.1"}]}],"ecosystem_specific":{"binaries":[{"libtiff6-32bit":"4.7.2-150600.3.29.1","libtiff-devel":"4.7.2-150600.3.29.1","libtiff6":"4.7.2-150600.3.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2853-1.json"}}],"schema_version":"1.7.5"}