I just got a forwarded copy of a note to oss-security@, at end. Reading the linked issue, I know there were multiple issues with proposed patches, and I'm very reluctant to take a patch from other than upstream.
I am wondering if there is a plan for 4.7.2, as reviewing commits looks like mostly fixes and CI stuff. Alternatively, I wonder if anyone has identified the commits by sha1 that should be cherry-picked, or if this is a theoretical DOS that isn't worth worrying about. I am 10% of the way to understanding the merges, but only 10%. ---------------------------------------- From: Ryo utomo <[email protected]> Subject: [oss-security] [CVE-2026-36849] libtiff: Denial of Service via large SamplesPerPixel tag To: [email protected] Date: Tue, 16 Jun 2026 17:13:49 -0700 (17 hours, 8 minutes, 21 seconds ago) Hi, I would like to disclose CVE-2026-36849, a denial of service vulnerability in libtiff. == Summary == An issue in libtiff v4.7.1 allows an attacker to cause a denial of service via a crafted TIFF file containing a large SamplesPerPixel tag value. == Affected Versions == libtiff v4.7.1 and prior == Patch == https://gitlab.com/gitlab-org/build/omnibus-mirror/libtiff/-/commit/eedba405d3695b52faae65994c5904f228eca0bf == References == - CVE: CVE-2026-36849 - Issue: https://gitlab.com/libtiff/libtiff/-/work_items/781 Regards, Satriyo Utomo (aleens-lab) _______________________________________________ Tiff mailing list [email protected] https://lists.osgeo.org/mailman/listinfo/tiff
