CVE-2023-52356Disclosure(libtiff / enterprise_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • libtiff

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-01); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
enterprise_linuxlibtiff

3 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-01: 1Mentions · 2026-04-10: 1Technical Details · 2026-04-01: 104-0104-10
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-011
Disclosure1
2026-04-101
General1
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    General

    libtiff CVE-2023-52356 crashes apps with a single malicious TIFF. Still unpatched on many Rocky/Ubuntu/SUSE boxes. Read more: 👉 https://tinyurl.com/2sphv8h8 #RockyLinux https://t.co/Bl7KOquKbn

    Post summary

    CVE‑2023‑52356 causes application crashes when processing a single malicious TIFF file; many systems have not yet applied a patch, though no exploit tools, PoC, or active exploitation activity are described.

    0000077
    1.5K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 ONNX, Path Traversal via Symlink, #CVE-2023-52356 (Medium) https://dailycve.com/onnx-path-traversal-via-symlink-cve-2023-52356-medium/

    Post summary

    The post announces a path traversal vulnerability in ONNX via symbolic links (CVE‑2023‑52356), indicating medium severity and linking to a dailyCVE article for details.

    0000079
    175 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Applibtifflibtiff---
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more