CVE-2026-4775Disclosure(debian / debian_linux)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch debian debian_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • enterprise_linux
  • hardened_images
  • libtiff

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-24); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
debian_linuxenterprise_linuxhardened_imageslibtiff

7 versions affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-24: 2Mentions · 2026-07-21: 1Patch / Workaround · 2026-07-21: 1Technical Details · 2026-03-24: 203-2407-21
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-242
Disclosure2
2026-07-211
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4775 A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a… https://www.cve.org/CVERecord?id=CVE-2026-4775

    Post summary

    The announcement details CVE-2026-4775 as a signed integer overflow in libtiff but offers no PoC, exploit code, or patch information.

    0000175
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4775 Integer Overflow Vulnerability in libtiff Library Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4775

    Post summary

    The post announces CVE-2026-4775, noting an integer overflow in libtiff that could lead to remote code execution; however, it does not offer a PoC, patch, or evidence of active exploitation.

    0000132
    4.0K followersView on X
  • Security Bug Aggregator@BugsAggregator
    Patch

    [501144544] Patch CVE-2026-4775 in libtiff http://crbug.com/501144544

    Post summary

    The text announces that a patch for CVE‑2026‑4775 affecting libtiff has been published.

    00000292
    3.5K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Applibtifflibtiff---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhathardened_images---

Explore more