Red Hat released Important security updates for libtiff to address CVE-2026-12912, a heap-based buffer overflow that can be triggered by a crafted PixarLog-compressed TIFF image. The flaw occurs when decoding images with PIXARLOGDATAFMT_8BITABGR and a stride of 3: horizontalAccumulate8abgr expands 3-byte input triplets into 4-byte output pixels, while PixarLogDecode advances the output pointer by only 3 bytes. Because TIFFScanlineSize can also return an undersized buffer for this configuration, applications that allocate buffers according to documented guidance may write past the end of the heap buffer by roughly one image-width byte per scan line.
The issue affects applications that explicitly select the vulnerable output format and read PixarLog-compressed TIFF files with SamplesPerPixel=3, while TIFFReadRGBAImage is not directly affected. Red Hat said the bug has been addressed across multiple supported product streams, including RHEL 9.4, RHEL 9.2, and RHEL 8.6 support channels, with updated packages such as libtiff-4.4.0-12.el9_4.6, libtiff-4.4.0-8.el9_2.6, and libtiff-4.0.9-21.el8_6.3 released for affected architectures and variants including SAP, AUS, EUS, and Extended Life Cycle offerings.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat published the Important RHSA-2026:61657 security advisory for affected RHEL 7 systems using compat-libtiff3, addressing CVE-2026-12912. The advisory remediates the heap-based buffer overflow triggered by crafted PixarLog-compressed TIFF images.
Red Hat published RHSA-2026:58556, an Important libtiff security advisory for Red Hat Enterprise Linux 9.4 update channels including SAP Solutions, AUS, and Extended Life Cycle variants, to remediate CVE-2026-12912. The advisory released libtiff 4.4.0-12.el9_4.6 packages for x86_64, aarch64, ppc64le, and s390x.
Red Hat published RHSA-2026:58554, an Important libtiff security advisory for Red Hat Enterprise Linux 9.2 SAP, AUS, and Extended Life Cycle offerings, addressing CVE-2026-12912. Updated libtiff 4.4.0-8.el9_2.6 packages were released across multiple architectures and product variants.
Red Hat published RHSA-2026:58545, an Important libtiff security advisory for Red Hat Enterprise Linux 8.6 support channels, to fix CVE-2026-12912. The update released libtiff 4.0.9-21.el8_6.3 packages for affected x86_64 and i686 package sets.
Red Hat published RHSA-2026:58553, an Important libtiff security advisory for Red Hat Enterprise Linux 8.8 update channels including Extended Life Cycle Long Life, Telecommunications Update Service, and Update Services for SAP Solutions, addressing CVE-2026-12912. The advisory released libtiff 4.0.9-29.el8_8.3 packages across supported x86_64, i686, and ppc64le variants.
Red Hat documented CVE-2026-12912 in Bugzilla entry 2492871 as a heap-based buffer overflow in libtiff when decoding crafted PixarLog-compressed TIFF images with the PIXARLOGDATAFMT_8BITABGR output format. The report described the pointer-advance mismatch, undersized TIFFScanlineSize result, and proof-of-concept-triggered heap overflow.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.