---
title: "CVE-2025-8534\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-8534?format=md
keywords: index, follow
---

# CVE-2025-8534

Publication date 5 August 2025

Last updated 7 August 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**2.5 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2025-8534?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability classified as problematic was found in libtiff 4.6.0. This
vulnerability affects the function PS\_Lvl2page of the file tools/tiff2ps.c
of the component tiff2ps. The manipulation leads to null pointer
dereference. It is possible to launch the attack on the local host. The
complexity of an attack is rather high. The exploitation appears to be
difficult. The exploit has been disclosed to the public and may be used.
The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is
recommended to apply a patch to fix this issue. One of the maintainers
explains, that "[t]his error only occurs if DEFER\_STRILE\_LOAD
(defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-8534?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| qtwebengine-opensource-src | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| texmaker | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| gdal | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |
| neuron | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| tiff | 26.04 LTS resolute | Fixed 4.7.0-3ubuntu2 |
| 25.10 questing | Fixed 4.7.0-3ubuntu2 |
| 25.04 plucky | Fixed 4.5.1+git230720-4ubuntu4.1 |
| 24.04 LTS noble | Fixed 4.5.1+git230720-4ubuntu2.3 |
| 22.04 LTS jammy | Fixed 4.3.0-6ubuntu0.11 |
| 20.04 LTS focal | Fixed 4.1.0+git191117-2ubuntu0.20.04.14+esm1  Ubuntu Pro |
| 18.04 LTS bionic | Fixed 4.0.9-5ubuntu0.10+esm8  Ubuntu Pro |
| 16.04 LTS xenial | Fixed 4.0.6-1ubuntu0.8+esm18  Ubuntu Pro |
| 14.04 LTS trusty | Fixed 4.0.3-7ubuntu0.11+esm15  Ubuntu Pro |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

texmaker added an embedded copy of libtiff in bionic

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2025-8534?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2025-8534?format=md)

**Base score**

1.1 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | High |
  | Attack requirements | None |
  | Privileges required | Low |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 1.1 · Low |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8534)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-8534)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-8534)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-8534)

### Related Ubuntu Security Notices (USN)

+ [USN-7707-1](https://usn.ubuntu.com/USN-7707-1)
+ LibTIFF vulnerabilities
+ 20 August 2025

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-8534>
* <https://gitlab.com/libtiff/libtiff/-/issues/718>
* <https://gitlab.com/libtiff/libtiff/-/merge_requests/746>
* <http://www.libtiff.org/>
* <https://drive.google.com/file/d/15JPA3kLYiYD-nRNJ8y8HmnYjhv9NE7k6/view?usp=drive_link>
* <https://gitlab.com/libtiff/libtiff/-/commit/6ba36f159fd396ad11bf6b7874554197736ecc8b>
* <https://vuldb.com/?ctiid.318664>
* <https://vuldb.com/?id.318664>
* <https://vuldb.com/?submit.617831>
