CVE-2026-12912: Heap-based Buffer Overflow in Red Hat Red Hat Enterprise Linux 10
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
AI Analysis
Technical Summary
CVE-2026-12912 is a heap-based buffer overflow vulnerability in the libtiff library on Red Hat Enterprise Linux 10. The flaw occurs during decoding of PixarLog-compressed TIFF images using the PIXARLOGDATAFMT_8BITABGR output format with a particular stride value, which can cause memory corruption. Exploitation could allow a remote attacker to execute arbitrary code or cause a denial of service. The vulnerability is tracked as CWE-122. Red Hat has issued security advisories and released updated libtiff packages (version 4.7.1-2.4.hum1 and 4.6.0-8.el10_2.4) that fix this issue.
Potential Impact
Successful exploitation of this vulnerability could lead to arbitrary code execution or denial of service on affected systems running Red Hat Enterprise Linux 10. The CVSS v3.1 base score is 7.3 (high severity), reflecting high impact on confidentiality, integrity, and availability. The attack vector requires local access with low privileges and user interaction, but the attacker can cause significant system compromise.
Mitigation Recommendations
Red Hat has released official security updates for libtiff that address CVE-2026-12912. Users should apply the updated libtiff packages (e.g., libtiff-4.7.1-2.4.hum1 or libtiff-4.6.0-8.el10_2.4) as provided in Red Hat advisories RHSA-2026:34890 and RHSA-2026:41892. Applying these updates fully mitigates the vulnerability. No additional vendor-recommended mitigations are currently indicated.
CVE-2026-12912: Heap-based Buffer Overflow in Red Hat Red Hat Enterprise Linux 10
Description
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
CVSS v3.1
Score 7.3high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-12912 is a heap-based buffer overflow vulnerability in the libtiff library on Red Hat Enterprise Linux 10. The flaw occurs during decoding of PixarLog-compressed TIFF images using the PIXARLOGDATAFMT_8BITABGR output format with a particular stride value, which can cause memory corruption. Exploitation could allow a remote attacker to execute arbitrary code or cause a denial of service. The vulnerability is tracked as CWE-122. Red Hat has issued security advisories and released updated libtiff packages (version 4.7.1-2.4.hum1 and 4.6.0-8.el10_2.4) that fix this issue.
Potential Impact
Successful exploitation of this vulnerability could lead to arbitrary code execution or denial of service on affected systems running Red Hat Enterprise Linux 10. The CVSS v3.1 base score is 7.3 (high severity), reflecting high impact on confidentiality, integrity, and availability. The attack vector requires local access with low privileges and user interaction, but the attacker can cause significant system compromise.
Mitigation Recommendations
Red Hat has released official security updates for libtiff that address CVE-2026-12912. Users should apply the updated libtiff packages (e.g., libtiff-4.7.1-2.4.hum1 or libtiff-4.6.0-8.el10_2.4) as provided in Red Hat advisories RHSA-2026:34890 and RHSA-2026:41892. Applying these updates fully mitigates the vulnerability. No additional vendor-recommended mitigations are currently indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-22T15:36:26.194Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-12912","vendor":"Red Hat"}]
Threat ID: 6a42a9a827e9c797193249f2
Added to database: 06/29/2026, 17:21:44 UTC
Last enriched: 08/11/2026, 17:33:22 UTC
Last updated: 08/13/2026, 15:40:27 UTC
Views: 106
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.