CVE-2025-61144Improper Restriction of Operations within the Bounds of a Memory Buffer in Libtiff

Severity
7.3HIGHNVD
OSV5.5
EPSS
0.0%
top 91.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateMar 23

Description

libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages4 packages

Patches

🔴Vulnerability Details

3
OSV
tiff vulnerabilities2026-03-23
OSV
CVE-2025-61144: libtiff up to v42026-02-23
GHSA
GHSA-m6xw-mq4p-x7xv: libtiff up to v42026-02-23

📋Vendor Advisories

4
Ubuntu
LibTIFF vulnerabilities2026-03-23
Red Hat
libtiff: libtiff: Denial of Service via buffer overflow2026-02-23
Microsoft
libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.2026-02-10
Debian
CVE-2025-61144: tiff - libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSepa...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-61144 Impact, Exploitability, and Mitigation Steps | Wiz