Vulnerability Description
An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://gist.github.com/okyfh/fbc5a37cade358361d80f6a498560cfa
- https://gitlab.com/libtiff/libtiff/-/commit/94affc5cf54111312f9891eb77accb93eebc
FAQ
What is CVE-2026-52492?
CVE-2026-52492 is a vulnerability with a CVSS score of 7.8 (HIGH). An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow duri...
How severe is CVE-2026-52492?
CVE-2026-52492 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-52492?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.