CVE-2026-52492

Publication date 24 August 2026

Last updated 2 September 2026


Ubuntu priority

Description

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

Status

Package Ubuntu Release Status


Access our resources on patching vulnerabilities