Multiple Vulnerabilities in LibTIFF Affect QT WebEngine, Texmaker, and GDAL

Multiple Vulnerabilities in LibTIFF Affect QT WebEngine, Texmaker, and GDAL

First seen 29 May 2026, 18:41 UTC Ubuntu 79% similarity 57.8

Article Content

Browse articles
ThreatCluster

Recent vulnerabilities have been discovered in QT WebEngine, Texmaker, and GDAL, all stemming from the vendored LibTIFF. These vulnerabilities allow attackers to potentially crash the applications, execute arbitrary code, or obtain sensitive information through specially crafted TIFF image metadata. The issues are classified as denial of service vulnerabilities, affecting users of these applications across various systems. Affected users are advised to update their systems to mitigate the risks associated with these vulnerabilities. The vulnerabilities were disclosed on May 28, 2026, and are part of a broader security advisory from Ubuntu. Users are encouraged to apply standard system updates to ensure protection. No specific CVEs have been mentioned in the articles.

Key Points: • QT WebEngine, Texmaker, and GDAL are vulnerable due to issues in the vendored LibTIFF. • Attackers can exploit these vulnerabilities to cause denial of service or execute arbitrary code. • Users should update their systems to the latest package versions to mitigate risks.

ThreatCluster AI

Timeline

2026-05-28
Vulnerabilities disclosed in QT WebEngine
QT WebEngine was found to have vulnerabilities due to improper handling of TIFF metadata, allowing potential denial of service and code execution.
Article 1 (Ubuntu)
2026-05-28
Vulnerabilities disclosed in Texmaker
Texmaker was reported to have similar vulnerabilities related to LibTIFF, potentially leading to crashes and arbitrary code execution.
Article 2 (Ubuntu)
2026-05-28
Vulnerabilities disclosed in GDAL
GDAL also suffers from vulnerabilities due to LibTIFF, allowing for denial of service and sensitive information exposure.
Article 3 (Ubuntu)

Community

Browse all →