
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-8177 is a buffer overflow vulnerability in LibTIFF affecting all versions up to and including 4.7.0. The flaw resides in the setrow function within tools/thumbnail.c, where improper memory buffer handling allows a local attacker to trigger a classic buffer overflow. It was published on July 26, 2025, and assigned a CVSS v3.1 base score of 7.8 (High) (Red Hat CVE, Feedly). Notably, this vulnerability only affects LibTIFF versions that are no longer supported by the upstream maintainer (Feedly).
The root cause is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-120 (Buffer Copy without Checking Size of Input — Classic Buffer Overflow). The vulnerable setrow function in tools/thumbnail.c performs a buffer copy operation without adequately validating the size of the input, allowing an attacker to write beyond the allocated buffer boundary. Exploitation requires local access with low privileges and no user interaction. A patch commit (e8c9d6c616b19438695fd829e58ae4fde5bfbc22) and an associated issue report are publicly available on the LibTIFF GitLab repository (LibTIFF GitLab Commit, LibTIFF GitLab Issue).
Successful exploitation could allow a local attacker with low privileges to compromise the confidentiality, integrity, and availability of the affected system. Potential consequences include arbitrary code execution, system instability or crashes, and unauthorized access to sensitive data processed by LibTIFF. The scope is limited to the local system running a vulnerable LibTIFF version, with no direct network-based lateral movement vector, though code execution could facilitate further privilege escalation (Red Hat CVE, Feedly).
A proof-of-concept reference is publicly available via the LibTIFF GitLab issue tracker, though no weaponized exploit or exploit kit has been reported (LibTIFF GitLab Issue). There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term (Feedly). No specific threat actor attribution has been reported.
thumbnail utility from the LibTIFF tools package. Check installed package versions using commands such as dpkg -l libtiff* or rpm -qa | grep tiff.setrow function when processed by tools/thumbnail.thumbnail tool against the malicious TIFF file (e.g., thumbnail malicious.tiff output.tiff), causing the setrow function to perform an out-of-bounds write.thumbnail binary or any application linking against LibTIFF 4.7.0 or earlier when processing TIFF files.core.*) generated by LibTIFF-linked processes./var/log/syslog, /var/log/messages) showing segmentation fault or abort signals from thumbnail or LibTIFF-dependent applications; application crash reports referencing tools/thumbnail.c or setrow.dpkg -l libtiff*, rpm -qa | grep tiff, or equivalent).The primary remediation is to apply the upstream patch commit e8c9d6c616b19438695fd829e58ae4fde5bfbc22 to the LibTIFF source, or upgrade to a patched package version provided by your Linux distribution. Multiple distributions have released updated packages: Ubuntu (USN-7707-1), Fedora 42, openSUSE/SUSE, Amazon Linux 2 (ALAS2-2025-2965), Oracle Linux, Red Hat (RHSA-2025:21407), and Mageia (Ubuntu Advisory, Red Hat Errata, Amazon Linux). As a workaround where patching is not immediately possible, restrict local user access to systems running vulnerable LibTIFF versions and avoid processing untrusted TIFF files with the thumbnail utility. Implementing least-privilege principles and monitoring for unusual process crashes are also recommended interim measures.
The vulnerability received coverage from Linux security news aggregators and distribution security teams, with advisories issued by Ubuntu, Red Hat, Fedora, SUSE, Amazon Linux, Oracle Linux, and Mageia (Ubuntu Advisory, Red Hat Errata). Pro-Linux.de and LinuxSecurity.com published advisory summaries, and the Yocto Project security mailing list flagged the issue for embedded Linux users (Feedly). No significant independent researcher commentary or social media debate has been observed beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."