{"id":"openSUSE-SU-2026:21289-1","summary":"Security update for tiff","details":"This update for tiff fixes the following issues\n\n- CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog-compressed TIFF image (bsc#1269779).\n- CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value\n  (bsc#1268434).\n\nChanges for tiff:\n\n- Update to 4.7.2:\n\n Software configuration changes:\n\n * cmake: Fix bundle identifiers to use reverse-DNS format\n * cmake: Fix and improve Apple framework build support\n * cmake: Use TurboJPEG CONFIG by default (issue #767)\n * cmake: changes related to 8-/12-bit modes\n * cmake: Replace CMath::CMath with direct link to avoid export.\n * Support for iOS-derived builds\n * Simplify cmake byte order version check\n * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions\n * configure.ac: Require bootstrap with at least Autoconf 2.71.\n\n Bug fixes:\n\n * Handle negative TIFFReadFile results before state updates (issue #854)\n * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip\n * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777)\n * tif_dirwrite.c: add integer overflow checks to allocation size calculations\n * tif_print.c: add integer overflow checks to allocation size calculations\n * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop\n * DumpModeSeek: add bounds check to prevent OOB pointer advance\n * TIFFGrowStrips: fix use-after-free on partial realloc failure.\n * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it.\n * TIFFRGBAImage: avoid int overflows in put functions (issue #830)\n * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792)\n * tif_getimage: Widen pointer-offset arithmetic in tif_getimage\n * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798)\n * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753)\n * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831)\n * TIFFLinkDirectory() checks for IFD loops (issue #788)\n * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails.\n * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805)\n * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465)\n * tif_getimage: reject tile widths that would overflow toskew (issue #808)\n * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit.\n * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777).\n * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss-fuzz.com/issues/471328917)\n * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode\n * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755).\n * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749)\n * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892)\n * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826)\n * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773)\n * JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501)\n * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow\n * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850)\n * PixarLog: error out on invalid ABGR output buffer sizes.\n * PixarLog: complete ABGR bounds check for multi-row strip decoding.\n * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789).\n * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797)\n * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072)\n * OJPEG: fix integer overflow in subsampling buffer allocation.\n * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795).\n * OJPEG fix potential integer overflow/out-of-bounds access (issue #796).\n * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b)\n * fix null pointer deference in issue #782.\n * fix stack-overflow in issue #784.\n\n Other changes:\n\n * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739).\n * Harden integer size and offset calculations (issue #897)\n * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication\n * Move widening casts inside multiplication scope.\n * Lots of compiler warning fixes related to enabling more warning flags\n * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773)\n * TIFFFillStrip(): prevent harmless unsigned integer overflow\n","modified":"2026-07-13T18:24:57.143033090Z","published":"2026-07-10T08:42:03Z","related":["CVE-2026-12912","CVE-2026-36849","CVE-2026-4775"],"upstream":["CVE-2026-12912","CVE-2026-36849","CVE-2026-4775"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268434"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269779"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12912"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-36849"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4775"}],"affected":[{"package":{"name":"tiff","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/tiff&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.2-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"tiff-docs":"4.7.2-160000.1.1","libtiff-devel":"4.7.2-160000.1.1","libtiff-devel-docs":"4.7.2-160000.1.1","libtiff6":"4.7.2-160000.1.1","tiff":"4.7.2-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21289-1.json"}},{"package":{"name":"tiff-man","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/tiff-man&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.2-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"tiff":"4.7.2-160000.1.1","tiff-docs":"4.7.2-160000.1.1","libtiff-devel":"4.7.2-160000.1.1","libtiff-devel-docs":"4.7.2-160000.1.1","libtiff6":"4.7.2-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21289-1.json"}}],"schema_version":"1.7.5"}