Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 473
Alerts This Week
Warning Icon 1 473

SUSE tiff Important Buffer Overflow DoS Vuln 2026-22796-1

suse
Calendar Grey July 27, 2026
Scroller Suse
A critical security update for SUSE tiff addresses two issues, including a buffer overflow and a denial of service risk.
This article announces a security update for SUSE Linux Micro 6.0, addressing vulnerabilities in TIFF with fixes and enhancements in version 4.7.2, emphasizing the critical need fo...

Summary

## This update for tiff fixes the following issues: Update to version 4.7.2. Security issues fixed: * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Other updates and bugfixes: * Enable Lerc support in openSUSE (bsc#1257123). * Version 4.7.2: * Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds

References

* bsc#1257123

* bsc#1268434

* bsc#1269779

Cross-

* CVE-2026-12912

* CVE-2026-36849

CVSS scores:

* CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* SUSE Linux Micro 6.0

An update that solves two vulnerabilities and has one fix can now be installed.

##

* https://www.suse.com/security/cve/CVE-2026-12912.html

* https://www.suse.com/security/cve/CVE-2026-36849.html

* https://bugzilla.suse.com/show_bug.cgi?id=1257123

* https://bugzilla.suse.com/show_bug.cgi?id=1268434

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22796-1
Release Date: 2026-07-17T12:21:31Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.