Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97923.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-97923
Upstream
Published
2026-08-24T21:17:19Z
Modified
2026-09-08T05:27:28Z
Summary
CVE-2026-52492 affecting package libtiff 4.6.0-14
Details

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

References

Affected packages

Azure Linux:3 / libtiff

Package

Name
libtiff
Purl
pkg:rpm/azure-linux/libtiff

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
4.6.0-14

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97923.json"