Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

SUSE tiff Important Heap Overflow and DoS Vulnerabilities 2026-22886-1

suse
Calendar Grey July 27, 2026
Scroller Suse
Install the important security update for tiff addressing heap overflow and denial of service issues effectively.
SUSE released an important security update for TIFF addressing two vulnerabilities, including a heap buffer overflow and denial of service, alongside various bug fixes and enhancem...

Summary

## This update for tiff fixes the following issues Update to version 4.7.2. Security issues fixed: * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Other updates and bugfixes: * Enable Lerc support in openSUSE (bsc#1257123). * Version 4.7.2: * Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds

References

* bsc#1257123

* bsc#1268434

* bsc#1269779

Cross-

* CVE-2026-12912

* CVE-2026-36849

CVSS scores:

* CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* SUSE Linux Micro 6.1

An update that solves two vulnerabilities and has one fix can now be installed.

##

* https://www.suse.com/security/cve/CVE-2026-12912.html

* https://www.suse.com/security/cve/CVE-2026-36849.html

* https://bugzilla.suse.com/show_bug.cgi?id=1257123

* https://bugzilla.suse.com/show_bug.cgi?id=1268434

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22886-1
Release Date: 2026-07-21T16:29:17Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.