Back to Security Advisories
High 2026-07-22

Libtiff Security Update — AlmaLinux 9 (ALSA-2026:42668)

AlmaLinux 9

The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): * libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS…

The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.

Security Fix(es):

* libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912)

For more details about the security issue(s), including the impact, a CVSS…

Type:
security

Severity:
important

Release date:
2026-07-22

Description:
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.

Security Fix(es):

* libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 libtiff-4.4.0-18.el9_8.1.aarch64.rpm 3618810acf04686f78bc602bf7a4e888c5442992bd882c87f2935ad141fef401
aarch64 libtiff-tools-4.4.0-18.el9_8.1.aarch64.rpm 43c847e0ad74e3b255dd389d5e5583f71df041fba046a4c7609ea4e1f2e9dd5a
aarch64 libtiff-devel-4.4.0-18.el9_8.1.aarch64.rpm 497052c9fa80b809a675d4b134818fd28c9a3b07b6de2fe9e24a92f8c129ec39
i686 libtiff-devel-4.4.0-18.el9_8.1.i686.rpm 1f78eb29a57569a7d4b8d422da2db89521a09b2429ac135229a927b950956fb1
i686 libtiff-4.4.0-18.el9_8.1.i686.rpm 5b6a6d3f1c6f219f4f3a5d43df1e82908507f1c741c992fe6b42accf925660b5
ppc64le libtiff-devel-4.4.0-18.el9_8.1.ppc64le.rpm 14ea3dd33a1792baadcac2206b39fdafc1beecd4ba2545b402757162eac3feeb
ppc64le libtiff-tools-4.4.0-18.el9_8.1.ppc64le.rpm 71225677d8606f01efedad59669e94729675ee7f6bacd5f52f2a8a9204e4826e
ppc64le libtiff-4.4.0-18.el9_8.1.ppc64le.rpm e48c92c8f9b19a5e058d432746225f9da736323588d903a24c17150619382d34
s390x libtiff-4.4.0-18.el9_8.1.s390x.rpm 1cef6f48427829f1bdbc1fef0d8ab17fa7fb250c2b3e71ade3362491017c8c8f
s390x libtiff-devel-4.4.0-18.el9_8.1.s390x.rpm 5d00b353d9df874306193d6e4e29b78bae8b89f315497478b00dd96b02d3a020
s390x libtiff-tools-4.4.0-18.el9_8.1.s390x.rpm af800787a5d967d09edcf8dfe4333a5f5f577676075f8531dfebd07d330a8bc2
x86_64 libtiff-devel-4.4.0-18.el9_8.1.x86_64.rpm 162ba210d542bbf52951054f4d7869aac2a5e44acf47b2fe4ae985b2a2c2c854
x86_64 libtiff-4.4.0-18.el9_8.1.x86_64.rpm 5ee55075b2a1edd0a5524de18205ee6e64d6acc65e94a88b0d799c72c7fb2c44
x86_64 libtiff-tools-4.4.0-18.el9_8.1.x86_64.rpm c1b980eed075ea0cab1bafb36c8395ac8fde2b32710a1efacf425a251a2d370c

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System