CVE-2026-12912: Red Hat Enterprise Linux 10
High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:4.6.0-8.el10_2.4 (fixed in 0:4.6.0-8.el10_2.4)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:4.6.0-6.el10_0.4 (fixed in 0:4.6.0-6.el10_0.4)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:3.9.4-12.el7_9.3 (fixed in 0:3.9.4-12.el7_9.3)
- Red Hat Red Hat Enterprise Linux 8: before 0:3.9.4-16.el8_10 (fixed in 0:3.9.4-16.el8_10); before 0:4.0.9-38.el8_10 (fixed in 0:4.0.9-38.el8_10)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:3.9.4-13.el8_4.3 (fixed in 0:3.9.4-13.el8_4.3); before 0:4.0.9-18.el8_4.3 (fixed in 0:4.0.9-18.el8_4.3)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:3.9.4-13.el8_4.3 (fixed in 0:3.9.4-13.el8_4.3); before 0:4.0.9-18.el8_4.3 (fixed in 0:4.0.9-18.el8_4.3)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:3.9.4-13.el8_6.3 (fixed in 0:3.9.4-13.el8_6.3); before 0:4.0.9-21.el8_6.3 (fixed in 0:4.0.9-21.el8_6.3)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 0:3.9.4-13.el8_6.3 (fixed in 0:3.9.4-13.el8_6.3); before 0:4.0.9-21.el8_6.3 (fixed in 0:4.0.9-21.el8_6.3)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:3.9.4-13.el8_8.3 (fixed in 0:3.9.4-13.el8_8.3); before 0:4.0.9-29.el8_8.3 (fixed in 0:4.0.9-29.el8_8.3)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:3.9.4-13.el8_8.3 (fixed in 0:3.9.4-13.el8_8.3); before 0:4.0.9-29.el8_8.3 (fixed in 0:4.0.9-29.el8_8.3)
- Red Hat Red Hat Enterprise Linux 9: before 0:4.4.0-18.el9_8.1 (fixed in 0:4.4.0-18.el9_8.1)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:4.4.0-8.el9_2.6 (fixed in 0:4.4.0-8.el9_2.6)
- Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:4.4.0-12.el9_4.6 (fixed in 0:4.4.0-12.el9_4.6)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:4.4.0-13.el9_6.6 (fixed in 0:4.4.0-13.el9_6.6)
- Red Hat Red Hat Hardened Images: before 4.7.1-2.4.hum1 (fixed in 4.7.1-2.4.hum1)
- Red Hat Red Hat Openshift Ai 3.0: before 1790276886 (fixed in 1790276886); before 1790276884 (fixed in 1790276884); before 1790277045 (fixed in 1790277045); before 1790276889 (fixed in 1790276889); before 1790276974 (fixed in 1790276974)
- Red Hat Red Hat Openshift Ai 3.2: before 1790703497 (fixed in 1790703497); before 1790703506 (fixed in 1790703506); before 1790703590 (fixed in 1790703590); before 1790703568 (fixed in 1790703568); before 1790703586 (fixed in 1790703586); before 1790703494 (fixed in 1790703494)
- Red Hat Red Hat Openshift Ai 3.4: before 1790703542 (fixed in 1790703542)
Published 2026-06-29. Last modified 2026-10-02.