Red Hat issued Moderate-severity advisories for CVE-2023-52356, a libtiff flaw in TIFFReadRGBATileExt() that can trigger a segmentation fault and denial of service when a system processes a crafted TIFF file. Fixed packages include libtiff-4.4.0-13.el9_6.3 for supported RHEL 9.6 channels, libtiff-4.4.0-15.el9 for supported RHEL 9 releases, and libtiff-4.6.0-6.el10_0.2 and libtiff-4.6.0-6.el10_1.2 for RHEL 10.0 and 10.1 channels, respectively, across x86_64, aarch64, ppc64le, and s390x.
The remediation also follows earlier RHEL 8 container-image updates for Middleware, CUPS, and Camel K Operator deployments, which incorporated fixes for CVE-2023-52356 alongside libtiff heap-overflow issues CVE-2018-15209, CVE-2023-25433, and CVE-2023-6228. Organizations should apply the relevant RHEL updates and, for affected OpenShift and RHEL 8 container environments, pull revised base images and rebuild dependent images to ensure vulnerable libtiff components are replaced.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity RHSA-2026:7304 for RHEL 10.0 update channels, providing libtiff 4.6.0-6.el10_0.2. The update fixes CVE-2023-52356, which a crafted TIFF file can trigger to cause denial of service.
Red Hat published Moderate-severity RHSA-2026:7081 for RHEL 10 and associated lifecycle channels. The advisory supplied libtiff 4.6.0-6.el10_1.2 to remediate CVE-2023-52356.
Red Hat issued Moderate-severity RHSA-2026:5958 for supported RHEL 9.6 update channels. It provided libtiff 4.4.0-13.el9_6.3 to fix CVE-2023-52356, a TIFFReadRGBATileExt segmentation fault that can cause denial of service.
Red Hat published Moderate-severity advisory RHSA-2025:20801 for RHEL 9, shipping corrected libtiff build 4.4.0-15.el9. The update remediated an out-of-memory issue in TIFFRasterScanlineSize64 (CVE-2023-52355) and the TIFFReadRGBATileExt denial-of-service flaw (CVE-2023-52356).
Red Hat issued RHBA-2024:5569 updating RHEL 8-based Middleware Containers to address libtiff vulnerabilities covered by RHSA-2024:5079, including CVE-2023-52356. Red Hat advised customers to pull the new images, revise Dockerfiles or scripts, and rebuild dependent images.
Red Hat issued RHBA-2024:5462 to update the integration/camel-k-rhel8-operator-bundle image for RHEL 8-based Middleware Containers. The image incorporated fixes referenced in RHBA-2024:5387 for four libtiff vulnerabilities, including CVE-2023-52356.
Red Hat published RHBA-2024:5387 for an updated integration/camel-k-rhel8-operator image used with RHEL 8-based Middleware Containers. The update included fixes for CVE-2018-15209, CVE-2023-25433, CVE-2023-6228, and CVE-2023-52356; affected users were told to upgrade and rebuild dependent images.
Red Hat issued RHBA-2024:5367 updating the RHEL 8 rhel8/cups container image to address security issues referenced in RHSA-2024:5079, including multiple libtiff flaws. Red Hat advised users to upgrade the image and rebuild dependent container images.
Red Hat issued RHBA-2024:5115 to update RHEL 8-based Middleware Containers with backported fixes for libtiff vulnerabilities, including CVE-2018-15209, CVE-2023-25433, CVE-2023-6228, and CVE-2023-52356. Users were advised to upgrade base images, update image references, and rebuild dependent containers.
libtiff closed an issue reporting a TIFFReadRGBATileExt segmentation fault and merged commit 51558511 to add row and column validation for TIFFReadRGBATile and TIFFReadRGBAStrip. The maintainer determined the proof of concept used invalid API parameters and characterized the reported crash, later assigned CVE-2023-52356, as a usage issue rather than a security vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcegitlab.com
Open sourcegitlab.com
Open sourcecatalog.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.