Skip to content

CVE-2026-12912 on CTRL-OS 26.05

Aliases: CVE-2026-12912

Packages: libtiff

Status: In Progress

Advisory Information

A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).

Updates

2026-07-28 00:08 CEST

Metadata changes:

  • Status for package libtiff: “In Progress” (eb637b2e1362a2f3f8da0faf729d9d9528bda12f)

2026-07-20 18:56 CEST

Metadata changes:

  • Status for package libtiff: “Acknowledged

(Amended on: 2026-07-20 19:10 CEST)

2026-07-20 18:55 CEST

Metadata changes:

  • Status for package libtiff: “New