CVE-2026-52492

Public on 2026-08-24
Modified on 2026-08-26
Description
An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
3.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core compat-libtiff3 Not Affected
Amazon Linux 2 - Core libtiff Pending Fix
Amazon Linux 2023 libtiff Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L