Gdal: A flaw was found in the libtiff library. (CVE-2026-4775)
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.
AI Analysis
Technical Summary
CVE-2026-10118 affects the Poppler library's Splash backend by triggering an integer overflow in the tilingPatternFill function when rendering a malicious PDF. This overflow causes an undersized heap allocation followed by an out-of-bounds write, resulting in heap-based memory corruption. Successful exploitation can lead to arbitrary code execution, information disclosure, or denial of service within the context of the vulnerable application. The vulnerability requires an attacker to supply or trick a user into processing a crafted PDF file. Red Hat AI Inference Server 3.3.5 (ROCm) includes this vulnerable component. No official fix has been released yet, and Red Hat recommends avoiding untrusted PDF files as a mitigation.
Potential Impact
The vulnerability can allow an attacker to execute arbitrary code, disclose sensitive information, or cause denial of service in applications using the Poppler Splash backend for PDF rendering. This can compromise the confidentiality, integrity, and availability of the affected system within the scope of the application processing the malicious PDF. The attack vector requires local user interaction to open or process a crafted PDF file. The severity is critical due to the potential for full compromise of the application context.
Mitigation Recommendations
Red Hat has not released a patch or official fix for this vulnerability at this time. Users should mitigate risk by avoiding opening untrusted or suspicious PDF documents with applications that utilize the Poppler library for rendering. Limiting exposure to untrusted PDF content reduces the likelihood of exploitation. Monitor Red Hat advisories for updates regarding patches or official remediation.
Gdal: A flaw was found in the libtiff library. (CVE-2026-4775)
Description
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.
CVSS v3.1
Score 7.8high
Affected software
pkg:deb/ubuntu/gdal?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/tiff?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/tiff?arch=source&distro=esm-infra/xenialpkg:deb/ubuntu/gdal?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/tiff?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/neuron?arch=source&distro=bionicpkg:deb/ubuntu/qtwebengine-opensource-src?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/texmaker?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/tiff?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/neuron?arch=source&distro=focalpkg:deb/ubuntu/qtwebengine-opensource-src?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/texmaker?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/neuron?arch=source&distro=jammypkg:deb/ubuntu/tiff?arch=source&distro=jammypkg:deb/ubuntu/qtwebengine-opensource-src?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/texmaker?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/tiff?arch=source&distro=noblepkg:deb/ubuntu/qtwebengine-opensource-src?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/texmaker?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/qtwebengine-opensource-src?arch=source&distro=questingpkg:deb/ubuntu/texmaker?arch=source&distro=questingpkg:deb/ubuntu/tiff?arch=source&distro=questingpkg:deb/ubuntu/tiff?arch=source&distro=resolutepkg:deb/ubuntu/qtwebengine-opensource-src?arch=source&distro=esm-apps/resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-10118 affects the Poppler library's Splash backend by triggering an integer overflow in the tilingPatternFill function when rendering a malicious PDF. This overflow causes an undersized heap allocation followed by an out-of-bounds write, resulting in heap-based memory corruption. Successful exploitation can lead to arbitrary code execution, information disclosure, or denial of service within the context of the vulnerable application. The vulnerability requires an attacker to supply or trick a user into processing a crafted PDF file. Red Hat AI Inference Server 3.3.5 (ROCm) includes this vulnerable component. No official fix has been released yet, and Red Hat recommends avoiding untrusted PDF files as a mitigation.
Potential Impact
The vulnerability can allow an attacker to execute arbitrary code, disclose sensitive information, or cause denial of service in applications using the Poppler Splash backend for PDF rendering. This can compromise the confidentiality, integrity, and availability of the affected system within the scope of the application processing the malicious PDF. The attack vector requires local user interaction to open or process a crafted PDF file. The severity is critical due to the potential for full compromise of the application context.
Mitigation Recommendations
Red Hat has not released a patch or official fix for this vulnerability at this time. Users should mitigate risk by avoiding opening untrusted or suspicious PDF documents with applications that utilize the Poppler library for rendering. Limiting exposure to untrusted PDF content reduces the likelihood of exploitation. Monitor Red Hat advisories for updates regarding patches or official remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:20585
- Cve Count
- 1
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a16097ce29bf47b50648810
Added to database: 05/26/2026, 20:58:36 UTC
Last enriched: 08/14/2026, 23:28:02 UTC
Last updated: 09/14/2026, 22:01:35 UTC
Views: 98
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.