
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61143 is a NULL pointer dereference vulnerability in libtiff up to and including version 4.7.1, located in the libtiff/tif_open.c component. It was disclosed on February 23, 2026, and affects all libtiff releases through v4.7.1, as well as Microsoft's CBL-Mariner and Azure Linux packages (cbl2_libtiff_4.6.0-11 and azl3_libtiff_4.6.0-11). The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly, Microsoft MSRC).
The root cause is a NULL pointer dereference (CWE-476) triggered during file-opening operations in libtiff/tif_open.c. When libtiff processes a specially crafted TIFF file, it fails to properly validate a pointer before dereferencing it, causing the application to crash. Exploitation requires local access and user interaction — specifically, a user must open a malicious TIFF file. The upstream issue and an associated merge request (MR #755) are tracked on the libtiff GitLab repository (GitHub Gist, Feedly).
Successful exploitation results in a denial-of-service (DoS) condition, causing the affected application to crash when processing a malicious TIFF file. The impact is limited to availability (rated High), with no confidentiality or integrity impact. Any application that uses libtiff for TIFF file processing — including image editors, document converters, and media libraries — is at risk of crashing when a user opens a crafted file (Feedly).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.017%, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Nessus (plugin IDs 299824, 303755) and Qualys (IDs 917029, 916998, 6032619) (Feedly).
libtiff/tif_open.c during file-open operations, referencing the upstream bug report at GitLab issue #737 for technical details.tif_open.c code path, the NULL pointer is dereferenced, causing the application to crash and resulting in a denial-of-service condition (GitHub Gist, Feedly)./var/log/syslog or journalctl) referencing libtiff.Upgrade libtiff to a version newer than 4.7.1, which contains the fix for this vulnerability. Microsoft has released security updates for affected packages (azl3_libtiff_4.6.0-11 and cbl2_libtiff_4.6.0-11); apply these updates immediately. As a workaround, restrict users from opening untrusted or unknown TIFF files, and implement file type validation in environments where TIFF processing is required. Distribution-specific patches have been issued for Ubuntu (USN-8113-1), SUSE (SUSE-2026-1408-1), Amazon Linux 2 (ALAS2-2026-3196), and Mageia (Microsoft MSRC, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."