openSUSE-SU-2026:21289-1: important: Security update for tiff
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for tiff
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21289-1
Rating: important
References:
* bsc#1268434
* bsc#1269779
Cross-References:
* CVE-2026-12912
* CVE-2026-36849
* CVE-2026-4775
CVSS scores:
* CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-4775 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-4775 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 3 vulnerabilities and has 2 bug fixes can now be installed.
Description:
This update for tiff fixes the following issues
- CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog-compressed TIFF image (bsc#1269779).
- CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value
(bsc#1268434).
Changes for tiff:
- Update to 4.7.2:
Software configuration changes:
* cmake: Fix bundle identifiers to use reverse-DNS format
* cmake: Fix and improve Apple framework build support
* cmake: Use TurboJPEG CONFIG by default (issue #767)
* cmake: changes related to 8-/12-bit modes
* cmake: Replace CMath::CMath with direct link to avoid export.
* Support for iOS-derived builds
* Simplify cmake byte order version check
* Add additional warnings, primarily floating precision conversions and integer arithmetic conversions
* configure.ac: Require bootstrap with at least Autoconf 2.71.
Bug fixes:
* Handle negative TIFFReadFile results before state updates (issue #854)
* tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip
* tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777)
* tif_dirwrite.c: add integer overflow checks to allocation size calculations
* tif_print.c: add integer overflow checks to allocation size calculations
* tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop
* DumpModeSeek: add bounds check to prevent OOB pointer advance
* TIFFGrowStrips: fix use-after-free on partial realloc failure.
* Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it.
* TIFFRGBAImage: avoid int overflows in put functions (issue #830)
* tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792)
* tif_getimage: Widen pointer-offset arithmetic in tif_getimage
* putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798)
* putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753)
* TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831)
* TIFFLinkDirectory() checks for IFD loops (issue #788)
* Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails.
* TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805)
* TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465)
* tif_getimage: reject tile widths that would overflow toskew (issue #808)
* Fix integer overflow in _TIFFPartialReadStripArray on 32-bit.
* TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777).
* _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss-fuzz.com/issues/471328917)
* TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode
* _TIFFMergeFields(): avoid NULL ptr dereference (issue #755).
* Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749)
* JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892)
* JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826)
* JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773)
* JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501)
* tif_jpeg: reject mismatched JPEG data precision to avoid write overflow
* Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850)
* PixarLog: error out on invalid ABGR output buffer sizes.
* PixarLog: complete ABGR bounds check for multi-row strip decoding.
* PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789).
* PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797)
* TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072)
* OJPEG: fix integer overflow in subsampling buffer allocation.
* OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795).
* OJPEG fix potential integer overflow/out-of-bounds access (issue #796).
* ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b)
* fix null pointer deference in issue #782.
* fix stack-overflow in issue #784.
Other changes:
* Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739).
* Harden integer size and offset calculations (issue #897)
* TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication
* Move widening casts inside multiplication scope.
* Lots of compiler warning fixes related to enabling more warning flags
* Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773)
* TIFFFillStrip(): prevent harmless unsigned integer overflow
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1200=1
Package List:
- openSUSE Leap 16.0:
libtiff-devel-4.7.2-160000.1.1
libtiff-devel-docs-4.7.2-160000.1.1
libtiff6-4.7.2-160000.1.1
tiff-4.7.2-160000.1.1
tiff-docs-4.7.2-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-12912.html
* https://www.suse.com/security/cve/CVE-2026-36849.html
* https://www.suse.com/security/cve/CVE-2026-4775.html