Red Hat libtiff Update Blocks Crafted-TIFF Code Execution on RHEL 8

P1 — VALIDATE AND UPDATEHigh · 7.3 (CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Red Hat published RHSA-2026:69095 for CVE-2026-52490, a 7.3 High libtiff flaw on RHEL 8. Processing a crafted TIFF through the affected tiffcrop option path can cause arbitrary code execution; the fixed build is 4.0.9-39.el8_10.

Find tiffcrop And Untrusted TIFF Processing

What to do now: Identify RHEL 8 systems, services, scripts, containers, and user workflows that use libtiff-tools or tiffcrop on untrusted images, install the fixed packages, restart or redeploy dependent workloads as required, and validate.

Open the authoritative advisory

Last verified: 2026-09-21 UTC. Recheck the current authoritative advisory and entitled repository before changing production.

Scope And Authority

Product scopeRHEL 8 libtiff and libtiff-tools
AdvisoryRHSA-2026:69095
CVECVE-2026-52490
Authoritative release date2026-09-21 03:20:26 UTC
Authority revision date2026-09-21 03:20:59 UTC
Affected versionsRHEL 8 libtiff packages before 4.0.9-39.el8_10
Fixed versionlibtiff 4.0.9-39.el8_10
CVSS base score7.3 (CVSS v3.1)
CVSS severityHigh
Exploitation statusNot stated by Red Hat; no exploitation claim is inferred.

What Changed

Red Hat describes an out-of-bounds condition in tiffcrop command-option processing that can lead to arbitrary code execution when a crafted TIFF is processed. Applicability depends on the installed package and a reachable image-processing path; the High score alone does not establish exposure.

What To Validate Now

  1. Inventory. Locate RHEL 8 libtiff and libtiff-tools packages, direct or transitive consumers, image-processing services, upload paths, batch jobs, containers, and user workstations.
  2. Establish applicability. Confirm the exact Red Hat package NVR and whether crafted or externally supplied TIFF files can reach tiffcrop command-option processing.
  3. Remediate. Update libtiff and libtiff-tools to 4.0.9-39.el8_10 or a supported superseding Red Hat build; until complete, avoid tiffcrop on untrusted files or remove unused tools where approved.
  4. Validate. Confirm package NVRs in hosts and rebuilt images, restart or redeploy processes that loaded the old library where required, and test representative trusted image workflows.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

A host package update does not replace vulnerable copies inside immutable images or statically bundled applications. Test codecs and dependent workflows before broad deployment and preserve sample, log, and process evidence if suspicious input was handled.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, source advisory revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.