AZL-101736

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101736.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-101736
Upstream
  • CVE-2026-18495
Published
2026-09-11T18:16:56Z
Modified
2026-09-18T05:37:08Z
Summary
CVE-2026-18495 affecting package libtiff 4.6.0-14
Details

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the tiff2pdf utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit StripByteCounts value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.

References

Affected packages

Azure Linux:3 / libtiff

Package

Name
libtiff
Purl
pkg:rpm/azure-linux/libtiff

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
4.6.0-14

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101736.json"