Red Hat Product Errata RHSA-2026:19150 - Security Advisory Issued: 2026-05-19 Updated: 2026-05-19 RHSA-2026:19150 - Security Advisory Overview Updated Packages Synopsis Important: libtiff security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libtiff is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing (CVE-2026-4775) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2450768 - CVE-2026-4775 libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing CVEs CVE-2026-4775 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM libtiff-4.6.0-8.el10_2.1.src.rpm SHA-256: 225caeb69565eaa24a202f9f8b9f2c0a8f4ba52434824028cc2fea66bcd22f4c x86_64 libtiff-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: 7b93b51a7933f5d5a2ddc7ceef78abf03bec656b697c4a790ddd7911caa47935 libtiff-debuginfo-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: da5f09d98df4938b46f4a1e9b630777f39a61913f9a67cabcee7b5785ccfda76 libtiff-debugsource-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: d897eec3494a0e0e9a95fa641e0124c18dc2d375071579528ead7b5c8ebdb0d2 libtiff-devel-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: 667ba61f67ec4da2150715cebb90ee43d8bfdc2febb1193b2e0975b7ed1ce022 libtiff-tools-debuginfo-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: 03449455b381ef650f5617c261101fa099f9a521bd7484d9acb2c21f28338dfa Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM libtiff-4.6.0-8.el10_2.1.src.rpm SHA-256: 225caeb69565eaa24a202f9f8b9f2c0a8f4ba52434824028cc2fea66bcd22f4c x86_64 libtiff-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: 7b93b51a7933f5d5a2ddc7ceef78abf03bec656b697c4a790ddd7911caa47935 libtiff-debuginfo-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: da5f09d98df4938b46f4a1e9b630777f39a61913f9a67cabcee7b5785ccfda76 libtiff-debugsource-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: d897eec3494a0e0e9a95fa641e0124c18dc2d375071579528ead7b5c8ebdb0d2 libtiff-devel-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: 667ba61f67ec4da2150715cebb90ee43d8bfdc2febb1193b2e0975b7ed1ce022 libtiff-tools-debuginfo-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: 03449455b381ef650f5617c261101fa099f9a521bd7484d9acb2c21f28338dfa Red Hat Enterprise Linux for IBM z Systems 10 SRPM libtiff-4.6.0-8.el10_2.1.src.rpm SHA-256: 225caeb69565eaa24a202f9f8b9f2c0a8f4ba52434824028cc2fea66bcd22f4c s390x libtiff-4.6.0-8.el10_2.1.s390x.rpm SHA-256: 67455ff8e97242ce0e60eb544a4bc0c66a1256e8c0db0fb63a07af130bca2914 libtiff-debuginfo-4.6.0-8.el10_2.1.s390x.rpm SHA-256: b44b41ace404004089b58b9d5058b4a9ad04104d3a738bd4f4133c682a074be5 libtiff-debugsource-4.6.0-8.el10_2.1.s390x.rpm SHA-256: f7d83ef559a316fd94022c61692d8d155b265124448fdb11bfdc285b94b8f53a libtiff-devel-4.6.0-8.el10_2.1.s390x.rpm SHA-256: 6d3da74aa29c7a8dc858b1de26fb09da0943759588c1c648b4ee1a9e6c59c24e libtiff-tools-debuginfo-4.6.0-8.el10_2.1.s390x.rpm SHA-256: b5dfb41cfc234115b677fa5250fc168b4c4554b37d6e17ac55ed3bfb4d2d8c2c Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM libtiff-4.6.0-8.el10_2.1.src.rpm SHA-256: 225caeb69565eaa24a202f9f8b9f2c0a8f4ba52434824028cc2fea66bcd22f4c s390x libtiff-4.6.0-8.el10_2.1.s390x.rpm SHA-256: 67455ff8e97242ce0e60eb544a4bc0c66a1256e8c0db0fb63a07af130bca2914 libtiff-debuginfo-4.6.0-8.el10_2.1.s390x.rpm SHA-256: b44b41ace404004089b58b9d5058b4a9ad04104d3a738bd4f4133c682a074be5 libtiff-debugsource-4.6.0-8.el10_2.1.s390x.rpm SHA-256: f7d83ef559a316fd94022c61692d8d155b265124448fdb11bfdc285b94b8f53a libtiff-devel-4.6.0-8.el10_2.1.s390x.rpm SHA-256: 6d3da74aa29c7a8dc858b1de26fb09da0943759588c1c648b4ee1a9e6c59c24e libtiff-tools-debuginfo-4.6.0-8.el10_2.1.s390x.rpm SHA-256: b5dfb41cfc234115b677fa5250fc168b4c4554b37d6e17ac55ed3bfb4d2d8c2c Red Hat Enterprise Linux for Power, little endian 10 SRPM libtiff-4.6.0-8.el10_2.1.src.rpm SHA-256: 225caeb69565eaa24a202f9f8b9f2c0a8f4ba52434824028cc2fea66bcd22f4c ppc64le libtiff-4.6.0-8.el10_2.1.ppc64le.rpm SHA-256: c07534c5ed9a58fa4300b554a16ebc13fe304bbc0f2d4033e4a38ae928eb92fc libtiff-debuginfo-4.6.0-8.el10_2.1.ppc64le.rpm SHA-256: ff0d0d01bdbe2b5c9f591f8c62f90b15d827df29edb2c9ac50e21c3c072bc959 libtiff-debugsource-4.6.0-8.el10_2.1.ppc64le.rpm SHA-256: 8debf6e4b9aabf1865e94b5d49388a8f4c6eaeb9530e437f0e005d30731541b5 libtiff-devel-4.6.0-8.el10_2.1.ppc64le.rpm SHA-256: daf33e0e629a5754f0b058c2dbd7cfffde6c5341db807bb8dbd7c73689a52df0 libtiff-tools-debuginfo-4.6.0-8.el10_2.1.ppc64le.rpm SHA-256: 2e987e8cbcab78f4c49158ea77bd64e3bb4116cc9fe5acbeff9581b4525bc58a Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM libtiff-4.6.0-8.el10_2.1.src.rpm SHA-256: 225caeb69565eaa24a202f9f8b9f2c0a8f4ba52434824028cc2fea66bcd22f4c ppc64le libtiff-4.6.0-8.el10_2.1.ppc64le.rpm SHA-256: c07534c5ed9a58fa4300b554a16ebc13fe304bbc0f2d4033e4a38ae928eb92fc libtiff-debuginfo-4.6.0-8.el10_2.1.ppc64le.rpm SHA-256: ff0d0d01bdbe2b5c9f591f8c62f90b15d827df29edb2c9ac50e21c3c072bc959 libtiff-debugsource-4.6.0-8.el10_2.1.ppc64le.rpm SHA-256: 8debf6e4b9aabf1865e94b5d49388a8f4c6eaeb9530e437f0e005d30731541b5 libtiff-devel-4.6.0-8.el10_2.1.ppc64le.rpm SHA-256: daf33e0e629a5754f0b058c2dbd7cfffde6c5341db807bb8dbd7c73689a52df0 libtiff-tools-debuginfo-4.6.0-8.el10_2.1.ppc64le.rpm SHA-256: 2e987e8cbcab78f4c49158ea77bd64e3bb4116cc9fe5acbeff9581b4525bc58a Red Hat Enterprise Linux for ARM 64 10 SRPM libtiff-4.6.0-8.el10_2.1.src.rpm SHA-256: 225caeb69565eaa24a202f9f8b9f2c0a8f4ba52434824028cc2fea66bcd22f4c aarch64 libtiff-4.6.0-8.el10_2.1.aarch64.rpm SHA-256: c8fa168a4b4910f40f7311abf4686ecb9760695ba1dd7934727c8884af486f23 libtiff-debuginfo-4.6.0-8.el10_2.1.aarch64.rpm SHA-256: b1da25962790caab2fb93e7df590fd1ae9b56dbab0a8fa30b611287abef4cc0a libtiff-debugsource-4.6.0-8.el10_2.1.aarch64.rpm SHA-256: 7877a3a444a71e05d192f6c15d77d7b5dedf1c7661415c0ce62dd2194332ae41 libtiff-devel-4.6.0-8.el10_2.1.aarch64.rpm SHA-256: ef72b2d37911ed20dffd1c84750fbaff75059f320bb41e852f7ccb57b623cf3a libtiff-tools-debuginfo-4.6.0-8.el10_2.1.aarch64.rpm SHA-256: e778ae247c64684bd1e916c6d4177fa33a28753052466743b71f1a6d65f2c5d1 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM libtiff-4.6.0-8.el10_2.1.src.rpm SHA-256: 225caeb69565eaa24a202f9f8b9f2c0a8f4ba52434824028cc2fea66bcd22f4c aarch64 libtiff-4.6.0-8.el10_2.1.aarch64.rpm SHA-256: c8fa168a4b4910f40f7311abf4686ecb9760695ba1dd7934727c8884af486f23 libtiff-debuginfo-4.6.0-8.el10_2.1.aarch64.rpm SHA-256: b1da25962790caab2fb93e7df590fd1ae9b56dbab0a8fa30b611287abef4cc0a libtiff-debugsource-4.6.0-8.el10_2.1.aarch64.rpm SHA-256: 7877a3a444a71e05d192f6c15d77d7b5dedf1c7661415c0ce62dd2194332ae41 libtiff-devel-4.6.0-8.el10_2.1.aarch64.rpm SHA-256: ef72b2d37911ed20dffd1c84750fbaff75059f320bb41e852f7ccb57b623cf3a libtiff-tools-debuginfo-4.6.0-8.el10_2.1.aarch64.rpm SHA-256: e778ae247c64684bd1e916c6d4177fa33a28753052466743b71f1a6d65f2c5d1 Red Hat CodeReady Linux Builder for x86_64 10 SRPM x86_64 libtiff-debuginfo-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: da5f09d98df4938b46f4a1e9b630777f39a61913f9a67cabcee7b5785ccfda76 libtiff-debugsource-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: d897eec3494a0e0e9a95fa641e0124c18dc2d375071579528ead7b5c8ebdb0d2 libtiff-tools-4.6.0-8.el10_2.1.x86_64.rpm SHA-256: cce73a795b458d97e50b438bceb0ea477ef2239164547fa7fbb1715202515e88 libt
A signed integer overflow vulnerability (CVE-2026-4775, CVSS 7.8 HIGH) in libtiff can lead to arbitrary code execution or denial of service when processing malicious TIFF files. The vulnerability affects libtiff versions up to an unspecified point, including Red Hat Enterprise Linux 6.0 and 7.0. Red Hat has released a security update rated Important for RHEL 10; affected systems should apply the patch via the referenced Red Hat update channels.