CVE-2026-52492

Published: August 27, 2026Last modified: September 2, 2026

Description

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Notes

We do not provide the rgb2ycbcr utility.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTStiffNot affected (4.4.0-r1)
25 LTStiffNot affected (4.7.0-r0)
StreamtiffNot affected (4.4.0-r1)

References

ON THIS PAGE