Wiz Agents & Workflows are here

CVE-2025-9900
Rocky Linux vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2025-9900) was discovered in Libtiff 4.7.0, identified as a 'write-what-where' condition. The flaw is triggered when the library processes a specially crafted TIFF image file with abnormally large image height values in the file's metadata. The vulnerability was disclosed on September 23, 2025, affecting the TIFFReadRGBAImageOriented() function in the Libtiff library (NVD, Red Hat).

Technical details

The vulnerability exists in the raster decoding logic of Libtiff, specifically when processing paletted images with malformed metadata. The issue occurs in the TIFFReadRGBAImageOriented() function, which computes a pointer offset into the raster buffer using the formula: raster + (rheight - img.height) * rwidth. When an attacker supplies a large value for img.height (e.g., 0xFFFF) and a valid rheight (e.g., 256), the computation results in a large positive offset, causing the raster pointer to point beyond the allocated buffer. The vulnerability has received a CVSS v3.1 base score of 8.8 (High) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (Github POC, Snyk).

Impact

The vulnerability can be exploited to cause memory corruption, leading to denial of service (application crash) or potential arbitrary code execution with the permissions of the user running the application. The attacker has control over both the write address through the offset calculation and the written value through the image's color palette data (NVD, Github POC).

Mitigation and workarounds

The vulnerability has been fixed in Libtiff version 4.7.1, released on September 18, 2025. Users are advised to upgrade to this version or later. The fix addresses the buffer underflow crash in TIFFReadRGBAImageOriented(). For Ubuntu users, version 4.0.9-5ubuntu0.10+esm9 or higher contains the necessary security fixes (Snyk).

Additional resources


SourceThis report was generated using AI

Related Rocky Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-4111HIGH7.5
  • Rocky LinuxRocky Linux
  • libarchive
NoYesMar 13, 2026
CVE-2026-26130HIGH7.5
  • C#C#
  • dotnet-runtime-9.0-debuginfo
NoYesMar 10, 2026
CVE-2026-26127HIGH7.5
  • C#C#
  • Microsoft.NetCore.App.Runtime.win-arm64
NoYesMar 10, 2026
CVE-2025-12801MEDIUM6.5
  • Rocky LinuxRocky Linux
  • nfs-utils-lib-devel
NoYesMar 04, 2026
CVE-2026-26104MEDIUM5.5
  • NixOSNixOS
  • udisks2-iscsi
NoYesFeb 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management