CVE-2025-61145
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-61145 is a double free vulnerability in libtiff up to and including version 4.7.1, located in the tools/tiffcrop.c component. The flaw was disclosed on February 23, 2026, and affects all libtiff releases through v4.7.1. It carries a CVSS v3.1 base score of 5.0 (Medium), requiring local access, low privileges, and user interaction to exploit (Feedly, GitLab Issue).

Technical details

The vulnerability is classified as CWE-415 (Double Free), occurring when the same memory block is freed twice during execution within the tiffcrop tool's processing logic in tools/tiffcrop.c. An attacker must supply a specially crafted TIFF file to a user running the tiffcrop utility, triggering the erroneous double-free condition. A proof-of-concept and a corresponding merge request addressing the issue have been published on the libtiff GitLab repository (GitLab Issue, GitLab MR).

Impact

Successful exploitation causes a denial of service by crashing the tiffcrop application, potentially leading to system instability when processing malicious TIFF files. There is no impact on confidentiality or integrity — only availability is affected. The scope is limited to the local system and the process running tiffcrop, with no evidence of lateral movement potential (Feedly).

Exploitability

A proof-of-concept is publicly available via the libtiff GitLab issue tracker, referenced as an exploit by NVD. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is very low at approximately 0.017%, reflecting limited exploitation likelihood. Exploitation requires local access, low privileges, and user interaction (i.e., a user must open a crafted TIFF file with tiffcrop) (GitLab Issue, Feedly).

Exploitation steps

  1. Craft a malicious TIFF file: Create a specially crafted TIFF file designed to trigger the double-free condition in tiffcrop's memory management logic within tools/tiffcrop.c.
  2. Deliver the file to the target: Use social engineering or file-sharing mechanisms to get a local user on the target system to process the crafted TIFF file.
  3. Trigger execution: Induce the target user to run tiffcrop against the malicious file (e.g., tiffcrop malicious.tiff output.tiff).
  4. Achieve denial of service: The double-free condition is triggered during processing, causing the tiffcrop process to crash, resulting in application termination or potential system instability (GitLab Issue).

Indicators of compromise

  • Process: Unexpected crash or abnormal termination of the tiffcrop process when processing a TIFF file.
  • Logs: Application crash logs or core dump files generated by tiffcrop (e.g., core files in the working directory); system logs (e.g., /var/log/syslog) showing segmentation fault or double-free errors from the tiffcrop process.
  • File System: Presence of unusual or unexpected TIFF files submitted for processing; core dump files (e.g., core.tiffcrop.<pid>) in the working directory.

Mitigation and workarounds

Update libtiff to a version newer than 4.7.1 once a patched release is available; a fix has been proposed via GitLab merge request #753. Until patching is possible, disable or restrict use of the tiffcrop tool if it is not operationally required. Additionally, restrict local user permissions on systems that process TIFF files and implement input validation to reject untrusted TIFF files before processing (GitLab MR, Feedly). Amazon Linux 2 users can refer to the ALAS advisory for distribution-specific guidance (AWS ALAS).

Community reactions

The Yocto Project security mailing list has discussed the vulnerability in the context of embedded Linux distributions, indicating awareness in the embedded systems community (Yocto Security). Tenable has published Nessus detection plugins (IDs 299837 and 303084) for this vulnerability, and Microsoft's MSRC has also catalogued it. No significant public researcher commentary or media coverage has been identified beyond standard vulnerability tracking.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

tiff

Affected

sid

tiff: 4.7.1-1

Fixed

trixie

tiff

Affected

Ubuntu

Fixed

bionic (esm-apps)

qtwebengine-opensource-src

Unknown

bionic (esm-infra)

tiff: 4.0.9-5ubuntu0.10+esm9

Fixed

devel

tiff: 4.7.0-3ubuntu3

Fixed

focal (esm-apps)

qtwebengine-opensource-src

Unknown

focal (esm-infra)

tiff: 4.1.0+git191117-2ubuntu0.20.04.14+esm2

Fixed

jammy

tiff: 4.3.0-6ubuntu0.12

Fixed

jammy (esm-apps)

qtwebengine-opensource-src

Unknown

noble

tiff: 4.5.1+git230720-4ubuntu2.4

Fixed

RHEL / CentOS

Affected

RHEL 8

compat-libtiff3.src

Affected

RHEL 9

libtiff.src

Affected

RHEL 10

libtiff.src

Affected

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management