Back Linuxsecurity Fedora 43: tkimg Critical Libpng Libtiff Vulnerabilities 2025
This package contains a collection of image format handlers for the Tk photo image type, and a new image type, pixmaps. Update Information : Update to 2.1.0. Update bundled libpng, libtiff, to latest versions. Built against TCL/TK 9. Fix FTBFS.
This package contains a collection of image format handlers for the Tk
photo image type, and a new image type, pixmaps.
Update to 2.1.0. Update bundled libpng, libtiff, to latest versions. Built against TCL/TK 9. Fix FTBFS.
* Thu Dec 18 2025 Tom Callaway - 2.1.0-1 - update to 2.1.0 - update the bundled copy of libpng to 1.6.53 - update the bundled copy of libtiff to 4.7.1 - build for tcl/tk 9 * Fri Jul 25 2025 Fedora Release Engineering - 1.4.16-5 - Rebuilt for
* Thu Dec 18 2025 Tom Callaway - 2.1.0-1 - update to 2.1.0 - update the bundled copy of libpng to 1.6.53 - update the bundled copy of libtiff to 4.7.1 - build for tcl/tk 9 * Fri Jul 25 2025 Fedora Release Engineering - 1.4.16-5 - Rebuilt for
[ 1 ] Bug #2337800 - Please update the package for the 'Tcl/Tk 9.0' Fedora change [ 2 ] Bug #2366434 - CVE-2025-4638 tkimg: Improper Pointer Arithmetic in pcl [fedora-42] [ 3 ] Bug #2383825 - CVE-2025-8176 tkimg: LibTIFF Use-After-Free Vulnerability [fedora-42] [ 4 ] Bug #2383831 - CVE-2025-8177 tkimg: LibTIFF Buffer Overflow [fedora-42] [ 5 ] Bug #2385697 - tkimg: FTBFS in Fedora rawhide/f43 [ 6 ] Bug #2386206 - CVE-2024-13978 tkimg: LibTIFF Null Pointer Dereference [fedora-42] [ 7 ] Bug #2387669 - CVE-2025-8851 tkimg: LibTIFF Stack-based buffer overflow [fedora-42] Read the Full Advisory
[ 1 ] Bug #2337800 - Please update the package for the 'Tcl/Tk 9.0' Fedora change [ 2 ] Bug #2366434 - CVE-2025-4638 tkimg: Improper Pointer Arithmetic in pcl [fedora-42] [ 3 ] Bug #2383825 - CVE-2025-8176 tkimg: LibTIFF Use-After-Free Vulnerability [fedora-42] [ 4 ] Bug #2383831 - CVE-2025-8177 tkimg: LibTIFF Buffer Overflow [fedora-42] [ 5 ] Bug #2385697 - tkimg: FTBFS in Fedora rawhide/f43 [ 6 ] Bug #2386206 - CVE-2024-13978 tkimg: LibTIFF Null Pointer Dereference [fedora-42] [ 7 ] Bug #2387669 - CVE-2025-8851 tkimg: LibTIFF Stack-based buffer overflow [fedora-42]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-13b23a6952' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
