CVE-2025-61143Disclosure(libtiff / libtiff)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch libtiff libtiff systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libtiff

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-23)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
libtiff

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-03-23: 2Patch / Workaround · 2026-03-23: 2Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 1Technical Details · 2026-03-23: 102-2302-2403-23
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-231
Disclosure1
2026-02-241
Disclosure1
2026-03-232
Patch2
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical LibTIFF DoS vulnerabilities (CVE-2025-61143, CVE-2025-61144) patched for #Ubuntu 25.10, 24.04 LTS, 22.04 LTS, and earlier releases with Ubuntu Pro. Read more: 👉 https://tinyurl.com/yenkmaar #Security https://t.co/OzlfoSfvsJ

    Post summary

    Ubuntu releases have been patched for the LibTIFF DoS vulnerabilities CVE-2025-61143 and CVE-2025-61144; no exploit details or active attacks are reported.

    0001098
    1.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-61143 NULL Pointer Dereference Vulnerability in libtiff Through tif_open.c Up to v4.7.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-61143

    Post summary

    The text announces a NULL pointer dereference vulnerability in libtiff up to version 4.7.1 (CVE-2025-61143) and provides a link to a vulnerability details page.

    0000136
    4.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 URGENT: #Ubuntu Security Update 🚨 Patch now for LibTIFF DoS flaws (CVE-2025-61143, CVE-2025-61144) affecting Ubuntu 25.10 down to 14.04 LTS. Read more: 👉 https://tinyurl.com/ue8e2zbv #Security https://t.co/V7Cy3C0JeI

    Post summary

    Ubuntu announced a patch for two LibTIFF DoS vulnerabilities (CVE-2025-61143, CVE-2025-61144) impacting versions from 14.04 LTS to 25.10.

    00000123
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-61143 libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c. https://www.cve.org/CVERecord?id=CVE-2025-61143

    Post summary

    A NULL pointer dereference vulnerability was identified in libtiff up to version 4.7.1, affecting the tif_open.c component.

    00000125
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibtifflibtiff---

Explore more