
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61145 is a double free vulnerability in libtiff up to and including version 4.7.1, located in the tools/tiffcrop.c component. The flaw was disclosed on February 23, 2026, and affects all libtiff releases through v4.7.1. It carries a CVSS v3.1 base score of 5.0 (Medium), requiring local access, low privileges, and user interaction to exploit (Feedly, GitLab Issue).
The vulnerability is classified as CWE-415 (Double Free), occurring when the same memory block is freed twice during execution within the tiffcrop tool's processing logic in tools/tiffcrop.c. An attacker must supply a specially crafted TIFF file to a user running the tiffcrop utility, triggering the erroneous double-free condition. A proof-of-concept and a corresponding merge request addressing the issue have been published on the libtiff GitLab repository (GitLab Issue, GitLab MR).
Successful exploitation causes a denial of service by crashing the tiffcrop application, potentially leading to system instability when processing malicious TIFF files. There is no impact on confidentiality or integrity — only availability is affected. The scope is limited to the local system and the process running tiffcrop, with no evidence of lateral movement potential (Feedly).
A proof-of-concept is publicly available via the libtiff GitLab issue tracker, referenced as an exploit by NVD. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is very low at approximately 0.017%, reflecting limited exploitation likelihood. Exploitation requires local access, low privileges, and user interaction (i.e., a user must open a crafted TIFF file with tiffcrop) (GitLab Issue, Feedly).
tiffcrop's memory management logic within tools/tiffcrop.c.tiffcrop against the malicious file (e.g., tiffcrop malicious.tiff output.tiff).tiffcrop process to crash, resulting in application termination or potential system instability (GitLab Issue).tiffcrop process when processing a TIFF file.tiffcrop (e.g., core files in the working directory); system logs (e.g., /var/log/syslog) showing segmentation fault or double-free errors from the tiffcrop process.core.tiffcrop.<pid>) in the working directory.Update libtiff to a version newer than 4.7.1 once a patched release is available; a fix has been proposed via GitLab merge request #753. Until patching is possible, disable or restrict use of the tiffcrop tool if it is not operationally required. Additionally, restrict local user permissions on systems that process TIFF files and implement input validation to reject untrusted TIFF files before processing (GitLab MR, Feedly). Amazon Linux 2 users can refer to the ALAS advisory for distribution-specific guidance (AWS ALAS).
The Yocto Project security mailing list has discussed the vulnerability in the context of embedded Linux distributions, indicating awareness in the embedded systems community (Yocto Security). Tenable has published Nessus detection plugins (IDs 299837 and 303084) for this vulnerability, and Microsoft's MSRC has also catalogued it. No significant public researcher commentary or media coverage has been identified beyond standard vulnerability tracking.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
qtwebengine-opensource-src
bionic (esm-infra)
tiff: 4.0.9-5ubuntu0.10+esm9
devel
tiff: 4.7.0-3ubuntu3
focal (esm-apps)
qtwebengine-opensource-src
focal (esm-infra)
tiff: 4.1.0+git191117-2ubuntu0.20.04.14+esm2
jammy
tiff: 4.3.0-6ubuntu0.12
jammy (esm-apps)
qtwebengine-opensource-src
noble
tiff: 4.5.1+git230720-4ubuntu2.4
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."