CVE-2025-8534
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-8534 is a null pointer dereference vulnerability in libtiff 4.6.0 affecting the PS_Lvl2page function in tools/tiff2ps.c of the tiff2ps component. The vulnerability was disclosed on August 5, 2025, and is classified as problematic (low severity). It is exploitable only locally and only under specific build or runtime conditions. It carries a CVSS v3.1 base score of 2.5 (Low) and a CVSS v4.0 base score of 1.1 (Low) (Red Hat Bugzilla, Red Hat CVE).

Technical details

The root cause is a null pointer dereference (CWE-476) combined with improper resource shutdown or release (CWE-404) in the PS_Lvl2page function of tools/tiff2ps.c. The flaw is triggered only when the DEFER_STRILE_LOAD build option is set to ON, or when TIFFOpen() is called with the "rD" option, as confirmed by a libtiff maintainer. An attacker with local access and low privileges must craft a malicious TIFF file and process it under these specific conditions to trigger the crash. A proof-of-concept exploit has been publicly disclosed via Google Drive and the libtiff GitLab issue tracker (Red Hat Bugzilla, libtiff GitLab Issue).

Impact

Successful exploitation results in a denial of service via application crash due to the null pointer dereference. There is no impact on confidentiality or integrity — only availability is affected, and only to a low degree. The scope is limited to the local host and the affected tiff2ps process; lateral movement or data exfiltration are not applicable to this vulnerability (Red Hat CVE, Oracle Bulletin).

Exploitability

A proof-of-concept exploit has been publicly disclosed and is available via Google Drive and the libtiff GitLab issue tracker. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.013% (0.000130), reflecting very low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (libtiff GitLab Issue, Red Hat CVE).

Exploitation steps

  1. Identify target: Confirm the target system has libtiff 4.6.0 installed and that the tiff2ps utility is compiled with DEFER_STRILE_LOAD=ON, or that applications call TIFFOpen() with the "rD" option.
  2. Craft malicious TIFF file: Prepare a specially crafted TIFF file designed to trigger the null pointer dereference in the PS_Lvl2page function when processed under the vulnerable configuration.
  3. Execute tiff2ps: Run tiff2ps <malicious.tiff> on the target system (requires local access with low privileges) under the vulnerable build/runtime conditions.
  4. Trigger crash: The PS_Lvl2page function dereferences a null pointer, causing the tiff2ps process to crash and resulting in a denial of service (libtiff GitLab Issue, Red Hat Bugzilla).

Indicators of compromise

  • Logs: Unexpected crash logs or segmentation fault messages from the tiff2ps process in system logs (e.g., /var/log/syslog, journalctl) referencing tools/tiff2ps.c or PS_Lvl2page.
  • Process: Abnormal termination of tiff2ps with a signal 11 (SIGSEGV) or similar null pointer dereference signal.
  • File System: Presence of unexpected or suspicious TIFF files in directories accessible to low-privileged users, particularly if tiff2ps is invoked automatically by scripts or services.

Mitigation and workarounds

Apply the upstream patch identified by commit 6ba36f159fd396ad11bf6b7874554197736ecc8b in the libtiff GitLab repository. As a workaround, avoid building libtiff with DEFER_STRILE_LOAD=ON and do not use TIFFOpen() with the "rD" option. Distribution-specific updates have been released for Fedora, Ubuntu (USN-7707-1), openSUSE, and Mageia; users should update to the patched libtiff package provided by their distribution. Oracle Solaris 11.4 users should apply the patch referenced in the January 2026 Oracle Solaris Third Party Bulletin (libtiff GitLab Commit, Ubuntu Advisory, Oracle Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management