CVE-2025-61143
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-61143 is a NULL pointer dereference vulnerability in libtiff up to and including version 4.7.1, located in the libtiff/tif_open.c component. It was disclosed on February 23, 2026, and affects all libtiff releases through v4.7.1, as well as Microsoft's CBL-Mariner and Azure Linux packages (cbl2_libtiff_4.6.0-11 and azl3_libtiff_4.6.0-11). The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly, Microsoft MSRC).

Technical details

The root cause is a NULL pointer dereference (CWE-476) triggered during file-opening operations in libtiff/tif_open.c. When libtiff processes a specially crafted TIFF file, it fails to properly validate a pointer before dereferencing it, causing the application to crash. Exploitation requires local access and user interaction — specifically, a user must open a malicious TIFF file. The upstream issue and an associated merge request (MR #755) are tracked on the libtiff GitLab repository (GitHub Gist, Feedly).

Impact

Successful exploitation results in a denial-of-service (DoS) condition, causing the affected application to crash when processing a malicious TIFF file. The impact is limited to availability (rated High), with no confidentiality or integrity impact. Any application that uses libtiff for TIFF file processing — including image editors, document converters, and media libraries — is at risk of crashing when a user opens a crafted file (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.017%, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Nessus (plugin IDs 299824, 303755) and Qualys (IDs 917029, 916998, 6032619) (Feedly).

Exploitation steps

  1. Craft a malicious TIFF file: Create a specially crafted TIFF file that triggers the NULL pointer dereference in libtiff/tif_open.c during file-open operations, referencing the upstream bug report at GitLab issue #737 for technical details.
  2. Deliver the file to the target: Use social engineering, email attachment, or a malicious web page to deliver the crafted TIFF file to a user on the target system.
  3. Induce the user to open the file: The vulnerability requires user interaction — the target must open the malicious TIFF file using an application that links against a vulnerable version of libtiff (≤ 4.7.1).
  4. Trigger the crash: When the application calls the affected tif_open.c code path, the NULL pointer is dereferenced, causing the application to crash and resulting in a denial-of-service condition (GitHub Gist, Feedly).

Indicators of compromise

  • Logs: Application crash logs or core dumps from processes that use libtiff (e.g., image viewers, document converters) when opening TIFF files; segmentation fault entries in system logs (/var/log/syslog or journalctl) referencing libtiff.
  • File System: Presence of unexpected or externally sourced TIFF files in user download directories or temporary folders.
  • Process: Abnormal termination (SIGSEGV/signal 11) of applications linked against libtiff when processing TIFF input; repeated application restarts triggered by crash handlers.

Mitigation and workarounds

Upgrade libtiff to a version newer than 4.7.1, which contains the fix for this vulnerability. Microsoft has released security updates for affected packages (azl3_libtiff_4.6.0-11 and cbl2_libtiff_4.6.0-11); apply these updates immediately. As a workaround, restrict users from opening untrusted or unknown TIFF files, and implement file type validation in environments where TIFF processing is required. Distribution-specific patches have been issued for Ubuntu (USN-8113-1), SUSE (SUSE-2026-1408-1), Amazon Linux 2 (ALAS2-2026-3196), and Mageia (Microsoft MSRC, Feedly).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72898CRITICAL10
  • NixOS logoNixOS
  • metabase
YesYesAug 10, 2026
CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util-sqlite-debuginfo
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util-odbc
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util-mysql
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management