CVE-2025-61144
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-61144 is a stack overflow vulnerability in libtiff up to and including version 4.7.1, triggered via the readSeparateStripsIntoBuffer function when processing specially crafted TIFF files. It was disclosed on February 23, 2026, with patches committed to the libtiff GitLab repository shortly after. The vulnerability carries a CVSS v3.1 base score of 7.3 (High), requiring low privileges and user interaction, with a local attack vector (Feedly, Microsoft MSRC).

Technical details

The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), specifically a stack overflow in the readSeparateStripsIntoBuffer function within libtiff (Feedly). An attacker crafts a malicious TIFF file that, when processed by an application using the vulnerable libtiff library, causes the function to write beyond the bounds of a stack-allocated buffer. Exploitation requires a local attacker with low privileges to induce a user or process to open the malicious file. The issue was reported via the libtiff GitLab issue tracker and addressed in two separate commits (GitHub Gist, libtiff commit 1, libtiff commit 2).

Impact

Successful exploitation can result in denial of service via application crash, potential arbitrary code execution if the attacker can control stack memory overwrite to redirect execution flow, or information disclosure through memory corruption (Feedly). Any system or application that processes untrusted TIFF files using libtiff versions up to 4.7.1 is at risk, including image viewers, document converters, and server-side media processing pipelines. The confidentiality, integrity, and availability impacts are all rated High per the CVSS scoring.

Exploitability

No public proof-of-concept exploit code has been confirmed, and there is no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is very low at approximately 0.018%, reflecting limited current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A GitLab issue (#740) serves as the primary public reference for the bug report (libtiff issue).

Exploitation steps

  1. Craft a malicious TIFF file: Create a specially crafted TIFF file with malformed strip data designed to trigger a stack overflow in the readSeparateStripsIntoBuffer function when parsed by libtiff.
  2. Deliver the file: Deliver the malicious TIFF to a target system via email attachment, file share, web upload, or other means, targeting an application that uses libtiff for image processing.
  3. Trigger processing: Induce a user or automated process (e.g., image viewer, document converter, thumbnail generator) to open or process the malicious TIFF file.
  4. Achieve impact: The stack overflow is triggered during strip buffer reading, potentially causing an application crash (DoS) or, if memory layout permits, overwriting return addresses or function pointers to redirect execution and achieve arbitrary code execution (libtiff issue, Feedly).

Indicators of compromise

  • Process: Unexpected crashes or segmentation faults in applications that process TIFF files (e.g., image viewers, converters, thumbnail services) linked against libtiff.
  • Logs: Application crash logs or core dumps referencing readSeparateStripsIntoBuffer in the stack trace; error messages from libtiff indicating malformed TIFF data.
  • File System: Presence of suspicious or unexpected TIFF files in upload directories, temporary folders, or user download locations.
  • Network: Unusual inbound file transfers of TIFF files to services that process images automatically, particularly from untrusted or external sources.

Mitigation and workarounds

The libtiff project has released patches addressing this vulnerability via two commits to the main repository (commits 09f53a86 and 88cf9dbb); users should upgrade to a version of libtiff that includes these fixes, beyond v4.7.1 (libtiff commit 1, libtiff commit 2). Distribution-specific updates have been issued for Ubuntu, SUSE, Amazon Linux 2, and Mageia, among others. As interim mitigations: restrict processing of TIFF files from untrusted sources, sandbox image-processing operations with minimal privileges, and implement file format validation before passing files to libtiff-based applications (Feedly).

Community reactions

Microsoft acknowledged the vulnerability through its Security Response Center advisory page, indicating relevance to Microsoft products shipping libtiff (e.g., Azure Linux packages azl3_libtiff_4.6.0-11 and cbl2_libtiff_4.6.0-11) (Microsoft MSRC). Multiple Linux distributions including Ubuntu, SUSE, Amazon Linux, and Mageia issued security advisories and updated packages. Security scanner vendors Tenable (Nessus) and Qualys added detection plugins for the vulnerability shortly after disclosure.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

tiff

Affected

sid

tiff: 4.7.1-1

Fixed

trixie

tiff

Affected

Ubuntu

Fixed

bionic (esm-apps)

qtwebengine-opensource-src

Unknown

bionic (esm-infra)

tiff: 4.0.9-5ubuntu0.10+esm10

Fixed

devel

tiff: 4.7.0-3ubuntu4

Fixed

focal (esm-apps)

qtwebengine-opensource-src

Unknown

focal (esm-infra)

tiff: 4.1.0+git191117-2ubuntu0.20.04.14+esm3

Fixed

jammy

tiff: 4.3.0-6ubuntu0.13

Fixed

jammy (esm-apps)

qtwebengine-opensource-src

Unknown

noble

tiff: 4.5.1+git230720-4ubuntu2.5

Fixed

RHEL / CentOS

Affected

RHEL 8

compat-libtiff3.src

Affected

RHEL 9

libtiff.src

Affected

RHEL 10

libtiff.src

Affected

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management