Red Hat Product Errata RHSA-2026:25910 - Security Advisory Issued: 2026-06-15 Updated: 2026-06-15 RHSA-2026:25910 - Security Advisory Overview Updated Packages Synopsis Important: libtiff security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libtiff is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing (CVE-2026-4775) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le Fixes BZ - 2450768 - CVE-2026-4775 libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing CVEs CVE-2026-4775 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 SRPM libtiff-4.0.3-35.el7_9.2.src.rpm SHA-256: bc891938123e45942372d835d5cd1f984095f4fede28dbea4f1624896c4004d8 x86_64 libtiff-4.0.3-35.el7_9.2.i686.rpm SHA-256: 3bebc12f5c4e6abe4da05790e17435e1655861ddffca305d52b698aa31faa785 libtiff-4.0.3-35.el7_9.2.x86_64.rpm SHA-256: 3a4ecd38c25f2082e9dba8462a73373c45f5fda2227caadbf08234a3b9ddcef1 libtiff-debuginfo-4.0.3-35.el7_9.2.i686.rpm SHA-256: 1e12a9a85cde13fe23ccb776cd658428954d876df18e552dbeb2f82c83471ce3 libtiff-debuginfo-4.0.3-35.el7_9.2.i686.rpm SHA-256: 1e12a9a85cde13fe23ccb776cd658428954d876df18e552dbeb2f82c83471ce3 libtiff-debuginfo-4.0.3-35.el7_9.2.x86_64.rpm SHA-256: c34c0f1243f71e8528c55c9460a9bd101de496c9dc0cc9306557e40c58c2f393 libtiff-debuginfo-4.0.3-35.el7_9.2.x86_64.rpm SHA-256: c34c0f1243f71e8528c55c9460a9bd101de496c9dc0cc9306557e40c58c2f393 libtiff-devel-4.0.3-35.el7_9.2.i686.rpm SHA-256: e1e49e5deeaff03945773e0976a14fa78c131583894581995bd9d7e408c17f52 libtiff-devel-4.0.3-35.el7_9.2.x86_64.rpm SHA-256: 5be8afcd5f331d50b2fe3e2f3b3e9d1b911007c8258011dbdb5a90ea83b92c74 libtiff-static-4.0.3-35.el7_9.2.i686.rpm SHA-256: a501a29fda5dadf353419a308c030f182bbe12e02eb8760d0f17b02db7eaf1c5 libtiff-static-4.0.3-35.el7_9.2.x86_64.rpm SHA-256: 763b743b5dad1d7a98bae679186adcabb85686c698a6fd434267eea811dbdae0 libtiff-tools-4.0.3-35.el7_9.2.x86_64.rpm SHA-256: d001ccdbfa991583101bf220670851812786a99599be5038843f623981bf2e49 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 SRPM libtiff-4.0.3-35.el7_9.2.src.rpm SHA-256: bc891938123e45942372d835d5cd1f984095f4fede28dbea4f1624896c4004d8 s390x libtiff-4.0.3-35.el7_9.2.s390.rpm SHA-256: 6016467b9ca02f75a9895ccd87bae7c3b2082edce1e30d1b7a1120b01e6b4d53 libtiff-4.0.3-35.el7_9.2.s390x.rpm SHA-256: 1d042551263aeca6e8a07dd95ccf78dd790dee3a6cecc3d9c7131871a0fbaeee libtiff-debuginfo-4.0.3-35.el7_9.2.s390.rpm SHA-256: 6a993c90d2c4b09560c6d602647296392231621f4bedab96a99d663eb11f018d libtiff-debuginfo-4.0.3-35.el7_9.2.s390.rpm SHA-256: 6a993c90d2c4b09560c6d602647296392231621f4bedab96a99d663eb11f018d libtiff-debuginfo-4.0.3-35.el7_9.2.s390x.rpm SHA-256: ae99ea7041613fcb3d37f8e2c0098bb7e5cf1e38441d2b9d7f6c91a0cd21f085 libtiff-debuginfo-4.0.3-35.el7_9.2.s390x.rpm SHA-256: ae99ea7041613fcb3d37f8e2c0098bb7e5cf1e38441d2b9d7f6c91a0cd21f085 libtiff-devel-4.0.3-35.el7_9.2.s390.rpm SHA-256: d5c3c5d1afd6d5b68aee29e76261e296775fe11cc937d94bc89364d4ed2df0bb libtiff-devel-4.0.3-35.el7_9.2.s390x.rpm SHA-256: bb894969947b8a32108a81be6044770f927d47e5da5c9cf01c9c7d2f1e775989 libtiff-static-4.0.3-35.el7_9.2.s390.rpm SHA-256: 252d3b8fc5040e9ce36a7ab179b583bdf034cfc3466d5eb4963bbc106f64dc61 libtiff-static-4.0.3-35.el7_9.2.s390x.rpm SHA-256: 7098931e336c77d0e813b7e5df096aa9b828eb4023079ab6ddfe68561760af4e libtiff-tools-4.0.3-35.el7_9.2.s390x.rpm SHA-256: d12964ad36c91b91da1a5ef68e3784d48d1ed75cb6be56f629895b6dfc161e8e Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 SRPM libtiff-4.0.3-35.el7_9.2.src.rpm SHA-256: bc891938123e45942372d835d5cd1f984095f4fede28dbea4f1624896c4004d8 ppc64 libtiff-4.0.3-35.el7_9.2.ppc.rpm SHA-256: f6eb2b37bfd3032f0bf17447f20af846b48516cc0d5e5798cd7ed2d2cc97bf5e libtiff-4.0.3-35.el7_9.2.ppc64.rpm SHA-256: ba85af9aac5576d877b54f5618e346897ed5a343198898dbbe4bdcad4399598e libtiff-debuginfo-4.0.3-35.el7_9.2.ppc.rpm SHA-256: 336b78293f0bd00fef2aca930cd37f360d60070fac98b0ed126ec7acb15561af libtiff-debuginfo-4.0.3-35.el7_9.2.ppc.rpm SHA-256: 336b78293f0bd00fef2aca930cd37f360d60070fac98b0ed126ec7acb15561af libtiff-debuginfo-4.0.3-35.el7_9.2.ppc64.rpm SHA-256: d766b4b3f060601543f0a31f90393f3fe6a6e91aa1ad196fa02e14f65594732a libtiff-debuginfo-4.0.3-35.el7_9.2.ppc64.rpm SHA-256: d766b4b3f060601543f0a31f90393f3fe6a6e91aa1ad196fa02e14f65594732a libtiff-devel-4.0.3-35.el7_9.2.ppc.rpm SHA-256: 8c1d15ac5210f9196eb79cd090ac5253b5c8f95d6a6e84e6188cb91439010a47 libtiff-devel-4.0.3-35.el7_9.2.ppc64.rpm SHA-256: 0c8075a73f80b53a5a9f14440d59ae23e95865a2766f7f09cfb33e25694ee944 libtiff-static-4.0.3-35.el7_9.2.ppc.rpm SHA-256: c05e16f4d4d1aacc2f9c7871410b86b19605c4431e29896e75565963434a34cb libtiff-static-4.0.3-35.el7_9.2.ppc64.rpm SHA-256: beabb21245e68277bf34543c6a8c03e5d4779aaf1fc5bfed9b1939d65ee3e0ca libtiff-tools-4.0.3-35.el7_9.2.ppc64.rpm SHA-256: 6665750baac26d0e121454dbc88038f4c034877bf5a88d03ab0178e15f460e9b Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 SRPM libtiff-4.0.3-35.el7_9.2.src.rpm SHA-256: bc891938123e45942372d835d5cd1f984095f4fede28dbea4f1624896c4004d8 ppc64le libtiff-4.0.3-35.el7_9.2.ppc64le.rpm SHA-256: 777e2cf00a1dc37d1484b6a9e0f94aaaa0d52c74f48e7c37394ab71d149c789e libtiff-debuginfo-4.0.3-35.el7_9.2.ppc64le.rpm SHA-256: 2e94638a54a1f8c8d5be2bd380e21f396da135aa149cc6bbcc46bcfc7bc1ba8a libtiff-debuginfo-4.0.3-35.el7_9.2.ppc64le.rpm SHA-256: 2e94638a54a1f8c8d5be2bd380e21f396da135aa149cc6bbcc46bcfc7bc1ba8a libtiff-devel-4.0.3-35.el7_9.2.ppc64le.rpm SHA-256: 35a7b6c9613e471ada32a47fc8d1b143eaf54a3bb77329ac120a2a90298ba397 libtiff-static-4.0.3-35.el7_9.2.ppc64le.rpm SHA-256: 55991a0cdf9ca9d4121a9f06363e634eee3f1389c7248bd69848e9fc5c5d7a4a libtiff-tools-4.0.3-35.el7_9.2.ppc64le.rpm SHA-256: b8eb854cede9218ef519ccf1dc5567a58e97499cc2edd76c304619d53fb210c2 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A signed integer overflow vulnerability (CVE-2026-4775, CVSS 7.8 HIGH) in libtiff can lead to arbitrary code execution or denial of service when processing malicious TIFF files. The vulnerability affects libtiff versions up to and including those shipped with Red Hat Enterprise Linux 7.0 and Debian Linux 11.0. The advisory provides updated packages for RHEL 7 Extended Lifecycle Support, such as libtiff-4.0.3-35.el7_9.2, to remediate the issue.