Skip to content
Ubuntu 26.04 introduces vital fixes for LibTIFF denial of service flaw

Ubuntu 26.04 introduces vital fixes for LibTIFF denial of service flaw

Linuxsecurity LinuxSecurity Advisories August 19, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

Several security issues were fixed in LibTIFF. Software Description: - tiff: Tag Image File Format (TIFF) library Details: USN 8113-1 fixed vulnerabilities in tiff. This update provides the corresponding fixes for Ubuntu 26.04 LTS. Original advisory details: It was discovered that LibTIFF did not properly handle memory when processing certain images. An attacker could possibly use this issue to cause LibTIFF to crash, resulting in a denial of service. (CVE-2025-61143) It was discovered that LibTIFF did not properly handle memory when processing malformed TIFF directories. An attacker could possibly use this issue to cause LibTIFF to crash, resulting in a denial of service. (CVE-2025-61144)

Several security issues were fixed in LibTIFF.

Software Description:

- tiff: Tag Image File Format (TIFF) library

USN 8113-1 fixed vulnerabilities in tiff. This update

provides the corresponding fixes for Ubuntu 26.04 LTS.

Original advisory details:

It was discovered that LibTIFF did not properly handle memory when

processing certain images. An attacker could possibly use this issue to

cause LibTIFF to crash, resulting in a denial of service. (CVE-2025-61143)

It was discovered that LibTIFF did not properly handle memory when

processing malformed TIFF directories. An attacker could possibly use this

issue to cause LibTIFF to crash, resulting in a denial of service.

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libtiff-opengl 4.7.0-3ubuntu5 libtiff-tools 4.7.0-3ubuntu5 libtiff6 4.7.0-3ubuntu5 libtiffxx6 4.7.0-3ubuntu5 In general, a standard system update will make all the necessary changes.

CVE-2025-61143, CVE-2025-61144

Ubuntu Security Notice USN-8113-2

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities