Introducing Wiz for Exposure Management: Unify, prioritize, and remediate exposures everywhere.

CVE-2025-8534
Linux Debian vulnerability analysis and mitigation

Overview

A vulnerability classified as problematic was found in libtiff 4.6.0, identified as CVE-2025-8534. The vulnerability affects the function PSLvl2page in the file tools/tiff2ps.c of the tiff2ps component. This issue was discovered in August 2025 and affects libtiff installations with DEFERSTRILE_LOAD enabled or when using TIFFOpen with the 'rD' option (VulDB).

Technical details

The vulnerability is a null pointer dereference issue (CWE-476) in the PSLvl2page function when processing TIFFTAGSTRIPBYTECOUNTS and TIFFTAGTILEBYTECOUNTS tags. The issue occurs specifically when DEFERSTRILE_LOAD (defer-strile-load:BOOL=ON) is enabled or when using TIFFOpen with the 'rD' option. The vulnerability has been assigned a CVSS v3.1 base score of 2.5 (LOW) with the vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L (VulDB, LibTIFF Commit).

Impact

The vulnerability affects the availability of the system by causing a null pointer dereference that typically results in a crash or program exit. The impact is limited to local attacks and requires specific conditions to be exploited (VulDB).

Mitigation and workarounds

The vulnerability has been patched in the LibTIFF repository with commit 6ba36f159fd396ad11bf6b7874554197736ecc8b. The fix involves adding checks for the return value of TIFFGetField() for TIFFTAGSTRIPBYTECOUNTS and TIFFTAGTILEBYTECOUNTS to avoid the null pointer dereference. It is recommended to apply this patch to affected systems (LibTIFF Commit).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management