CVE-2026-52492

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

Published 2026-08-24. Last modified 2026-09-09.