RLSA-2026:47183

Source
https://errata.rockylinux.org/RLSA-2026:47183
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2026:47183.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2026:47183
Upstream
  • CVE-2026-12912
Published
2026-08-03T12:01:09.862125Z
Modified
2026-08-03T12:30:05.346677411Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Important: compat-libtiff3 security update
Details

The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.

Security Fix(es):

  • libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:8 / compat-libtiff3

Package

Name
compat-libtiff3
Purl
pkg:rpm/rocky-linux/compat-libtiff3?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:3.9.4-16.el8_10
Database specific
{
    "yum_repository": "AppStream"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2026:47183.json"