
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4775 is a signed integer overflow vulnerability in the libtiff library that can lead to an out-of-bounds heap write, potentially enabling denial of service or arbitrary code execution. The flaw resides in the putcontig8bitYCbCr44tile function (and related functions such as putcontig8bitYCbCr42tile, putcontig8bitYCbCr22tile, and putcontig8bitYCbCr12tile) within tif_getimage.c. It was disclosed on March 24, 2026, and affects libtiff broadly, with confirmed impact on Red Hat Enterprise Linux 6–10, Debian Linux 11.0, and IBM Cloud Pak for Data System. It carries a CVSS v3.1 base score of 7.8 (High) (Red Hat CVE, Red Hat Bugzilla).
The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound). When processing a specially crafted TIFF file with an extremely large image width and specific YCbCr subsampling parameters (e.g., 4:4 subsampling), the calculation for the pointer progression variable (incr) overflows the 32-bit signed integer boundary. This results in an incorrect negative memory pointer progression, causing an out-of-bounds heap write. Exploitation requires user interaction — specifically, a victim must open a maliciously crafted TIFF file — and no special privileges are required. The attack vector is local (the file must be processed on the target system) (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation can result in high confidentiality, integrity, and availability impact on the affected system. An attacker who tricks a user into opening a crafted TIFF file could cause the application processing the file to crash (denial of service) or potentially execute arbitrary code in the context of the application. Any application or service that uses libtiff for image processing — including image viewers, document converters, and server-side media processing pipelines — is at risk. Lateral movement potential is limited given the local attack vector, but code execution could enable privilege escalation or further compromise of the affected host (Red Hat CVE, Red Hat Bugzilla).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.056% (0.000560), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. User interaction is required, which reduces the likelihood of mass exploitation, though the broad deployment of libtiff across Linux distributions and software ecosystems increases the overall attack surface (Red Hat CVE).
incr pointer progression variable to overflow a 32-bit signed integer during processing in putcontig8bitYCbCr44tile within tif_getimage.c..tif/.tiff files in user download directories, temporary folders, or email attachment staging areas; core dump files generated by libtiff-linked applications./var/log/messages, journalctl) referencing libtiff-linked processes; crash reports from image processing daemons.convert, tiff2pdf, libreoffice, image viewers) shortly after opening a TIFF file; unusual child processes spawned from image processing applications.Vendors have released patches across multiple distributions. Red Hat has issued security advisories for RHEL 7 through 10, including:
Additional patches have been issued for Debian (DSA-6303-1), Amazon Linux 2/2023, openSUSE/SUSE (SUSE-SU-2026:1965-1), AlmaLinux, Rocky Linux, Oracle Linux, and Mageia. IBM has addressed the issue in Cloud Pak for Data System (see IBM support page 7275772). The primary remediation is to apply the vendor-provided package update. No configuration-based workaround is available; organizations unable to patch immediately should restrict access to TIFF file processing and avoid opening TIFF files from untrusted sources (Red Hat RHSA-2026:12265, Red Hat RHSA-2026:12271, Red Hat RHSA-2026:14929, IBM Advisory).
The vulnerability received standard coverage across Linux security advisory channels, including LinuxSecurity.com, LinuxCompatible.org, and pro-linux.de, which published multiple advisories as patches rolled out across distributions. Detection plugins were rapidly developed by Tenable (Nessus) and Qualys, with over 30 scanner detection IDs created. No notable independent researcher commentary or significant social media discussion has been identified beyond routine vulnerability tracking (Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
qtwebengine-opensource-src
bionic (esm-infra)
tiff
devel
tiff
focal (esm-apps)
qtwebengine-opensource-src
focal (esm-infra)
tiff
jammy
tiff
jammy (esm-apps)
qtwebengine-opensource-src
noble
tiff
RHEL 8
:appstream:compat-libtiff3-0:3.9.4-15.el8_10.src
RHEL 9
:appstream:libtiff-0:4.2.0-3.el9_0.3.src
RHEL 10
libtiff-0:4.6.0-6.el10_0.3.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."