CVE-2026-52492
Publication date 24 August 2026
Last updated 2 September 2026
Ubuntu priority
Description
An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image