Skip to content

CVE-2026-4775 on CTRL-OS 26.05

Aliases: CVE-2026-4775

Packages: libtiff

Status: In Progress

Advisory Information

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

Updates

2026-07-28 00:07 CEST

Metadata changes:

  • Status for package libtiff: “In Progress” (eb637b2e1362a2f3f8da0faf729d9d9528bda12f)

(Amended on: 2026-07-28 00:08 CEST)

2026-07-20 19:02 CEST

Metadata changes:

  • Status for package libtiff: “Acknowledged

(Amended on: 2026-07-20 19:10 CEST)

2026-07-20 19:02 CEST

Metadata changes:

  • Status for package libtiff: “New