USN-8113-1

Source
https://ubuntu.com/security/notices/USN-8113-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8113-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8113-1
Upstream
Related
Published
2026-03-23T10:53:59Z
Modified
2026-03-24T12:14:26.188750Z
Summary
tiff vulnerabilities
Details

It was discovered that LibTIFF did not properly handle memory when processing certain images. An attacker could possibly use this issue to cause LibTIFF to crash, resulting in a denial of service. (CVE-2025-61143)

It was discovered that LibTIFF did not properly handle memory when processing malformed TIFF directories. An attacker could possibly use this issue to cause LibTIFF to crash, resulting in a denial of service. (CVE-2025-61144)

References

Affected packages

Ubuntu:22.04:LTS
tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.3.0-6ubuntu0.13?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.0-6ubuntu0.13

Affected versions

4.*
4.3.0-1
4.3.0-2
4.3.0-3
4.3.0-3build1
4.3.0-4
4.3.0-5
4.3.0-6
4.3.0-6ubuntu0.1
4.3.0-6ubuntu0.2
4.3.0-6ubuntu0.3
4.3.0-6ubuntu0.4
4.3.0-6ubuntu0.5
4.3.0-6ubuntu0.6
4.3.0-6ubuntu0.7
4.3.0-6ubuntu0.8
4.3.0-6ubuntu0.9
4.3.0-6ubuntu0.10
4.3.0-6ubuntu0.11
4.3.0-6ubuntu0.12

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.3.0-6ubuntu0.13"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.3.0-6ubuntu0.13"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.3.0-6ubuntu0.13"
        },
        {
            "binary_name": "libtiff5",
            "binary_version": "4.3.0-6ubuntu0.13"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.3.0-6ubuntu0.13"
        },
        {
            "binary_name": "libtiffxx5",
            "binary_version": "4.3.0-6ubuntu0.13"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8113-1.json"
cves_map
{
    "ecosystem": "Ubuntu:22.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61143"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61144"
        }
    ]
}
Ubuntu:24.04:LTS
tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.5.1+git230720-4ubuntu2.5?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.5.1+git230720-4ubuntu2.5

Affected versions

4.*
4.5.1+git230720-1ubuntu1
4.5.1+git230720-3ubuntu1
4.5.1+git230720-4ubuntu1
4.5.1+git230720-4ubuntu2
4.5.1+git230720-4ubuntu2.1
4.5.1+git230720-4ubuntu2.2
4.5.1+git230720-4ubuntu2.3
4.5.1+git230720-4ubuntu2.4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.5.1+git230720-4ubuntu2.5"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.5.1+git230720-4ubuntu2.5"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.5.1+git230720-4ubuntu2.5"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.5.1+git230720-4ubuntu2.5"
        },
        {
            "binary_name": "libtiff6",
            "binary_version": "4.5.1+git230720-4ubuntu2.5"
        },
        {
            "binary_name": "libtiffxx6",
            "binary_version": "4.5.1+git230720-4ubuntu2.5"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8113-1.json"
cves_map
{
    "ecosystem": "Ubuntu:24.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61143"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61144"
        }
    ]
}
Ubuntu:25.10
tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.7.0-3ubuntu3.1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.7.0-3ubuntu3.1

Affected versions

4.*
4.5.1+git230720-4ubuntu4
4.7.0-3ubuntu1
4.7.0-3ubuntu2
4.7.0-3ubuntu3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.7.0-3ubuntu3.1"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.7.0-3ubuntu3.1"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.7.0-3ubuntu3.1"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.7.0-3ubuntu3.1"
        },
        {
            "binary_name": "libtiff6",
            "binary_version": "4.7.0-3ubuntu3.1"
        },
        {
            "binary_name": "libtiffxx6",
            "binary_version": "4.7.0-3ubuntu3.1"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8113-1.json"
cves_map
{
    "ecosystem": "Ubuntu:25.10",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61143"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61144"
        }
    ]
}
Ubuntu:Pro:14.04:LTS
tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.0.3-7ubuntu0.11+esm17?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.3-7ubuntu0.11+esm17

Affected versions

4.*
4.0.2-4ubuntu3
4.0.3-5ubuntu1
4.0.3-6
4.0.3-6ubuntu1
4.0.3-7
4.0.3-7ubuntu0.1
4.0.3-7ubuntu0.2
4.0.3-7ubuntu0.3
4.0.3-7ubuntu0.4
4.0.3-7ubuntu0.6
4.0.3-7ubuntu0.7
4.0.3-7ubuntu0.8
4.0.3-7ubuntu0.9
4.0.3-7ubuntu0.10
4.0.3-7ubuntu0.11
4.0.3-7ubuntu0.11+esm1
4.0.3-7ubuntu0.11+esm2
4.0.3-7ubuntu0.11+esm3
4.0.3-7ubuntu0.11+esm4
4.0.3-7ubuntu0.11+esm5
4.0.3-7ubuntu0.11+esm6
4.0.3-7ubuntu0.11+esm7
4.0.3-7ubuntu0.11+esm8
4.0.3-7ubuntu0.11+esm9
4.0.3-7ubuntu0.11+esm10
4.0.3-7ubuntu0.11+esm11
4.0.3-7ubuntu0.11+esm12
4.0.3-7ubuntu0.11+esm13
4.0.3-7ubuntu0.11+esm14
4.0.3-7ubuntu0.11+esm15
4.0.3-7ubuntu0.11+esm16

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.0.3-7ubuntu0.11+esm17"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.0.3-7ubuntu0.11+esm17"
        },
        {
            "binary_name": "libtiff4-dev",
            "binary_version": "4.0.3-7ubuntu0.11+esm17"
        },
        {
            "binary_name": "libtiff5",
            "binary_version": "4.0.3-7ubuntu0.11+esm17"
        },
        {
            "binary_name": "libtiff5-alt-dev",
            "binary_version": "4.0.3-7ubuntu0.11+esm17"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.0.3-7ubuntu0.11+esm17"
        },
        {
            "binary_name": "libtiffxx5",
            "binary_version": "4.0.3-7ubuntu0.11+esm17"
        }
    ],
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8113-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:14.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61143"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61144"
        }
    ]
}
Ubuntu:Pro:16.04:LTS
tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.0.6-1ubuntu0.8+esm20?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.6-1ubuntu0.8+esm20

Affected versions

4.*
4.0.3-12.3ubuntu2
4.0.5-1
4.0.6-1
4.0.6-1ubuntu0.1
4.0.6-1ubuntu0.2
4.0.6-1ubuntu0.3
4.0.6-1ubuntu0.4
4.0.6-1ubuntu0.5
4.0.6-1ubuntu0.6
4.0.6-1ubuntu0.7
4.0.6-1ubuntu0.8
4.0.6-1ubuntu0.8+esm1
4.0.6-1ubuntu0.8+esm2
4.0.6-1ubuntu0.8+esm3
4.0.6-1ubuntu0.8+esm4
4.0.6-1ubuntu0.8+esm6
4.0.6-1ubuntu0.8+esm7
4.0.6-1ubuntu0.8+esm8
4.0.6-1ubuntu0.8+esm9
4.0.6-1ubuntu0.8+esm10
4.0.6-1ubuntu0.8+esm11
4.0.6-1ubuntu0.8+esm12
4.0.6-1ubuntu0.8+esm13
4.0.6-1ubuntu0.8+esm14
4.0.6-1ubuntu0.8+esm15
4.0.6-1ubuntu0.8+esm16
4.0.6-1ubuntu0.8+esm17
4.0.6-1ubuntu0.8+esm18
4.0.6-1ubuntu0.8+esm19

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.0.6-1ubuntu0.8+esm20"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.0.6-1ubuntu0.8+esm20"
        },
        {
            "binary_name": "libtiff5",
            "binary_version": "4.0.6-1ubuntu0.8+esm20"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.0.6-1ubuntu0.8+esm20"
        },
        {
            "binary_name": "libtiffxx5",
            "binary_version": "4.0.6-1ubuntu0.8+esm20"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8113-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:16.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61143"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61144"
        }
    ]
}
Ubuntu:Pro:18.04:LTS
tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.0.9-5ubuntu0.10+esm10?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.9-5ubuntu0.10+esm10

Affected versions

4.*
4.0.8-5
4.0.8-6
4.0.9-1
4.0.9-2
4.0.9-3
4.0.9-4
4.0.9-4ubuntu1
4.0.9-5
4.0.9-5ubuntu0.1
4.0.9-5ubuntu0.2
4.0.9-5ubuntu0.3
4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.5
4.0.9-5ubuntu0.6
4.0.9-5ubuntu0.7
4.0.9-5ubuntu0.8
4.0.9-5ubuntu0.9
4.0.9-5ubuntu0.10
4.0.9-5ubuntu0.10+esm1
4.0.9-5ubuntu0.10+esm2
4.0.9-5ubuntu0.10+esm3
4.0.9-5ubuntu0.10+esm4
4.0.9-5ubuntu0.10+esm5
4.0.9-5ubuntu0.10+esm6
4.0.9-5ubuntu0.10+esm7
4.0.9-5ubuntu0.10+esm8
4.0.9-5ubuntu0.10+esm9

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.0.9-5ubuntu0.10+esm10"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.0.9-5ubuntu0.10+esm10"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.0.9-5ubuntu0.10+esm10"
        },
        {
            "binary_name": "libtiff5",
            "binary_version": "4.0.9-5ubuntu0.10+esm10"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.0.9-5ubuntu0.10+esm10"
        },
        {
            "binary_name": "libtiffxx5",
            "binary_version": "4.0.9-5ubuntu0.10+esm10"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8113-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:18.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61143"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61144"
        }
    ]
}
Ubuntu:Pro:20.04:LTS
tiff

Package

Name
tiff
Purl
pkg:deb/ubuntu/tiff@4.1.0+git191117-2ubuntu0.20.04.14+esm3?arch=source&distro=esm-infra/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.0+git191117-2ubuntu0.20.04.14+esm3

Affected versions

4.*
4.0.10+git191003-1
4.1.0+git191117-1
4.1.0+git191117-2
4.1.0+git191117-2build1
4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.2
4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.4
4.1.0+git191117-2ubuntu0.20.04.5
4.1.0+git191117-2ubuntu0.20.04.6
4.1.0+git191117-2ubuntu0.20.04.7
4.1.0+git191117-2ubuntu0.20.04.8
4.1.0+git191117-2ubuntu0.20.04.9
4.1.0+git191117-2ubuntu0.20.04.10
4.1.0+git191117-2ubuntu0.20.04.11
4.1.0+git191117-2ubuntu0.20.04.12
4.1.0+git191117-2ubuntu0.20.04.13
4.1.0+git191117-2ubuntu0.20.04.14
4.1.0+git191117-2ubuntu0.20.04.14+esm1
4.1.0+git191117-2ubuntu0.20.04.14+esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libtiff-dev",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm3"
        },
        {
            "binary_name": "libtiff-opengl",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm3"
        },
        {
            "binary_name": "libtiff-tools",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm3"
        },
        {
            "binary_name": "libtiff5",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm3"
        },
        {
            "binary_name": "libtiff5-dev",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm3"
        },
        {
            "binary_name": "libtiffxx5",
            "binary_version": "4.1.0+git191117-2ubuntu0.20.04.14+esm3"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8113-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:20.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61143"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-61144"
        }
    ]
}