
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61144 is a stack overflow vulnerability in libtiff up to and including version 4.7.1, triggered via the readSeparateStripsIntoBuffer function when processing specially crafted TIFF files. It was disclosed on February 23, 2026, with patches committed to the libtiff GitLab repository shortly after. The vulnerability carries a CVSS v3.1 base score of 7.3 (High), requiring low privileges and user interaction, with a local attack vector (Feedly, Microsoft MSRC).
The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), specifically a stack overflow in the readSeparateStripsIntoBuffer function within libtiff (Feedly). An attacker crafts a malicious TIFF file that, when processed by an application using the vulnerable libtiff library, causes the function to write beyond the bounds of a stack-allocated buffer. Exploitation requires a local attacker with low privileges to induce a user or process to open the malicious file. The issue was reported via the libtiff GitLab issue tracker and addressed in two separate commits (GitHub Gist, libtiff commit 1, libtiff commit 2).
Successful exploitation can result in denial of service via application crash, potential arbitrary code execution if the attacker can control stack memory overwrite to redirect execution flow, or information disclosure through memory corruption (Feedly). Any system or application that processes untrusted TIFF files using libtiff versions up to 4.7.1 is at risk, including image viewers, document converters, and server-side media processing pipelines. The confidentiality, integrity, and availability impacts are all rated High per the CVSS scoring.
No public proof-of-concept exploit code has been confirmed, and there is no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is very low at approximately 0.018%, reflecting limited current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A GitLab issue (#740) serves as the primary public reference for the bug report (libtiff issue).
readSeparateStripsIntoBuffer function when parsed by libtiff.readSeparateStripsIntoBuffer in the stack trace; error messages from libtiff indicating malformed TIFF data.The libtiff project has released patches addressing this vulnerability via two commits to the main repository (commits 09f53a86 and 88cf9dbb); users should upgrade to a version of libtiff that includes these fixes, beyond v4.7.1 (libtiff commit 1, libtiff commit 2). Distribution-specific updates have been issued for Ubuntu, SUSE, Amazon Linux 2, and Mageia, among others. As interim mitigations: restrict processing of TIFF files from untrusted sources, sandbox image-processing operations with minimal privileges, and implement file format validation before passing files to libtiff-based applications (Feedly).
Microsoft acknowledged the vulnerability through its Security Response Center advisory page, indicating relevance to Microsoft products shipping libtiff (e.g., Azure Linux packages azl3_libtiff_4.6.0-11 and cbl2_libtiff_4.6.0-11) (Microsoft MSRC). Multiple Linux distributions including Ubuntu, SUSE, Amazon Linux, and Mageia issued security advisories and updated packages. Security scanner vendors Tenable (Nessus) and Qualys added detection plugins for the vulnerability shortly after disclosure.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
qtwebengine-opensource-src
bionic (esm-infra)
tiff: 4.0.9-5ubuntu0.10+esm10
devel
tiff: 4.7.0-3ubuntu4
focal (esm-apps)
qtwebengine-opensource-src
focal (esm-infra)
tiff: 4.1.0+git191117-2ubuntu0.20.04.14+esm3
jammy
tiff: 4.3.0-6ubuntu0.13
jammy (esm-apps)
qtwebengine-opensource-src
noble
tiff: 4.5.1+git230720-4ubuntu2.5
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."