CVE-2026-4775 Details
Description
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.
A signed integer overflow vulnerability has been identified in the libtiff library, specifically within the putcontig8bitYCbCr44tile function. This vulnerability arises when the function processes specially crafted TIFF files that have extremely large widths and specific YCbCr subsampling. The overflow occurs in the calculation of a pointer progression variable, causing memory pointers to incorrectly progress negatively. This flaw can be exploited by remote attackers to perform out-of-bounds writes to the heap, potentially leading to application crashes or arbitrary code execution.
Avoid processing untrusted or maliciously crafted TIFF files with applications that use the libtiff library. If it is necessary to process such files, consider running the applications in a sandboxed environment to limit the potential impact of exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | redhat-SADP |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libtiff libtiff | All versions |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
27 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 27, 2026 | CVE Modified | [email protected] |
| Jun 27, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 15, 2026 | CVE Modified | [email protected] |
| Jun 10, 2026 | CVE Modified | [email protected] |
| Jun 10, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 11, 2026 | CVE Modified | [email protected] |
| May 7, 2026 | CVE Modified | [email protected] |
| Apr 30, 2026 | CVE Modified | [email protected] |
| Apr 30, 2026 | CVE Modified | [email protected] |
| Apr 21, 2026 | Initial Analysis | [email protected] |
| Apr 17, 2026 | CVE Modified | CVE |
| Mar 24, 2026 | New CVE Received | [email protected] |