Red Hat released RHSA-2024:5079 for Red Hat Enterprise Linux 8 and RHEL 8.10 Extended Life Cycle, updating libtiff to remediate four crafted-TIFF vulnerabilities: CVE-2018-15209, CVE-2023-25433, CVE-2023-6228, and CVE-2023-52356. The updated packages are available for x86_64, s390x, ppc64le, and aarch64; related tools packages are provided through CodeReady Linux Builder.
The flaws are heap-based buffer overflows in libtiff APIs and utilities, including tiff2pdf, tiffcp, and tiffcrop. Processing a malicious TIFF can crash affected programs and cause denial of service; CVE-2023-25433 stems from incorrect buffer-size updating after rotateImage() in tiffcrop. Red Hat assessed the issues primarily as requiring crafted-file processing and rated the advisory Moderate, while support and remediation status varies across RHEL releases and the compat-libtiff3 package.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2026:7081, providing a fixed libtiff package for Red Hat Enterprise Linux 10 to remediate CVE-2023-52356.
Red Hat released RHSA-2026:5958 with a fixed libtiff package for the Red Hat Enterprise Linux 9.6 Extended Update Support stream.
Red Hat released RHSA-2025:20801, providing a fixed libtiff package for Red Hat Enterprise Linux 9 to address CVE-2023-52356.
Red Hat issued RHBA-2024:5568 updating RHEL 8-based Middleware Container images, including JBoss EAP 7.4 OpenJDK 17 OpenShift and runtime images, with fixes from RHSA-2024:5079 for four libtiff vulnerabilities. Customers were advised to retrieve the updated images, update Dockerfiles or scripts, and rebuild dependent container images.
Red Hat issued RHBA-2024:5567 to update RHEL 8-based Middleware Containers container images with the libtiff security fixes from RHSA-2024:5079, covering CVE-2018-15209, CVE-2023-25433, CVE-2023-6228, and CVE-2023-52356. Red Hat advised customers to pull the updated images and rebuild dependent container images.
Red Hat issued RHBA-2024:5483 to update the RHEL 8 rhel8/go-toolset and ubi8/go-toolset container images with fixes from RHSA-2024:5079 for four libtiff vulnerabilities, including CVE-2023-6228 and CVE-2023-52356. Users were advised to upgrade the images and rebuild dependent container images.
Red Hat issued RHBA-2024:5449, updating RHEL 8 container images to incorporate the libtiff security fixes from RHSA-2024:5079, including CVE-2023-6228 and CVE-2023-52356. Red Hat advised users to upgrade their base images and rebuild dependent container images.
Red Hat issued RHBA-2024:5087 to update OpenShift Dev Spaces 3 container images with backported fixes from RHSA-2024:5079 for four libtiff vulnerabilities, including CVE-2018-15209, CVE-2023-6228, and CVE-2023-52356. Users were advised to upgrade the images and rebuild dependent container images.
Red Hat issued RHSA-2024:5079, a Moderate-security libtiff update for RHEL 8 and RHEL 8.10 Extended Life Cycle deployments. The update remediated CVE-2018-15209, CVE-2023-25433, CVE-2023-6228, and CVE-2023-52356.
Red Hat released RHSA-2024:2289 for Red Hat Enterprise Linux 9, providing a libtiff fix for CVE-2023-6228, a heap-based buffer overflow in tiffcp's cpStripToTile() function.
Red Hat published CVE-2023-52356, describing a heap-based buffer overflow in libtiff's TIFFReadRGBATileExt() API that can be triggered by a crafted TIFF file to crash an affected program.
Guilherme de Almeida Suckevicz reported CVE-2023-6228, a heap-based buffer overflow in libtiff's tiffcp cpStripToTile() function. A crafted TIFF file processed by tiffcp can trigger an application crash.
Laura Pardo reported CVE-2018-15209 to Red Hat as Bugzilla 1614051. The flaw is a heap-based buffer overflow in LibTIFF's ChopUpSingleUncompressedStrip function that a crafted TIFF file can trigger, causing an application crash or denial of service.
Red Hat released RHSA-2026:7304 with a fixed libtiff package for the Red Hat Enterprise Linux 10.0 Extended Update Support stream.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
15 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.