Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.5
CVE-2023-52355: Rootio-tiff: Malicious TIFF Files Can Crash Root Devices
CVE-2023-52355 · published 11 days ago
Summary
The rootio-tiff package, used on Root devices, had a bug that could cause a device to crash if it processed a specially crafted TIFF file. This is now fixed in updated versions of the package. Update your Root device to the latest version of rootio-tiff to protect against this issue.
What to do
- Update rootio-tiff to version 4.2.0-1+deb11u7.root.io.13.
- Update rootio-tiff to version 4.5.0-6+deb12u3.root.io.18.
- Update rootio-tiff to version 4.5.0-6+deb12u4.root.io.19.
- Update rootio-tiff to version 4.2.0-1+deb11u8.root.io.16.
- Update tiff to version 4.2.0-1+deb11u8.root.io.16.
- Update tiff to version 4.5.0-6+deb12u4.aikido.21.
- Update rootio-tiff to version 4.5.0-6+deb12u4.aikido.21.
- Update tiff to version 4.5.0-6+deb12u4.aikido.22.
- Update rootio-tiff to version 4.5.0-6+deb12u4.aikido.22.
- Update debian tiff to version 4.5.1+git230720-4.
- Update libtiff libtiff to version 4.6.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:Debian:11 | – | rootio-tiff |
< 4.2.0-1+deb11u7.root.io.13 < 4.2.0-1+deb11u8.root.io.16 Fix: upgrade to 4.2.0-1+deb11u7.root.io.13
|
| Root:Debian:12 | – | rootio-tiff |
< 4.5.0-6+deb12u3.root.io.18 < 4.5.0-6+deb12u4.root.io.19 < 4.5.0-6+deb12u4.aikido.21 < 4.5.0-6+deb12u4.aikido.22 Fix: upgrade to 4.5.0-6+deb12u3.root.io.18
|
| – | red hat | red hat enterprise linux 10 | All versions |
| – | red hat | red hat enterprise linux 9 | All versions |
| – | red hat | red hat ai inference server 3.2 | All versions |
| Root:Debian:11 | – | tiff |
< 4.2.0-1+deb11u8.root.io.16 Fix: upgrade to 4.2.0-1+deb11u8.root.io.16
|
| Root:Debian:12 | – | tiff |
< 4.5.0-6+deb12u4.aikido.21 < 4.5.0-6+deb12u4.aikido.22 Fix: upgrade to 4.5.0-6+deb12u4.aikido.21
|
| – | red hat | red hat discovery 2 | All versions |
| – | red hat | red hat enterprise linux 6 | All versions |
| – | red hat | red hat enterprise linux 7 | All versions |
| – | red hat | red hat enterprise linux 8 | All versions |
| – | libtiff | libtiff |
< 4.6.0 cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:* |
| – | redhat | enterprise_linux |
8.0 9.0 cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
| – | red hat | red hat enterprise linux 9.6 extended update support | All versions |
| Debian:12 | debian | tiff | All versions |
| Debian:13 | debian | tiff |
< 4.5.1+git230720-4 Fix: upgrade to 4.5.1+git230720-4
|
| Debian:14 | debian | tiff |
< 4.5.1+git230720-4 Fix: upgrade to 4.5.1+git230720-4
|
| Ubuntu:22.04:LTS | canonical | tiff | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | gdal | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | tiff | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | tiff | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | gdal | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | tiff | All versions |
| Ubuntu:18.04:LTS | canonical | neuron | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | qtwebengine-opensource-src | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | texmaker | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | tiff | All versions |
| Ubuntu:20.04:LTS | canonical | neuron | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | qtwebengine-opensource-src | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | texmaker | All versions |
| Ubuntu:22.04:LTS | canonical | neuron | All versions |
| Ubuntu:22.04:LTS | canonical | qtwebengine-opensource-src | All versions |
| Ubuntu:22.04:LTS | canonical | texmaker | All versions |
Original advisory text
CVE-2023-52355 in tiff - Patched by Root
Root has patched CVE-2023-52355 in the tiff package for Root:Debian:11. Multiple fixed versions available.
References
- https://ubuntu.com/security/CVE-2023-52355 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-52355 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-52355 Third Party Advisory
- https://gitlab.com/libtiff/libtiff/-/merge_requests/553 Third Party Advisory
- https://gitlab.com/libtiff/libtiff/-/issues/621
- https://access.redhat.com/errata/RHSA-2026:41892 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:3461 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23078 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23079 vendor-advisory x_refsource_REDHAT
- https://gitlab.com/libtiff/libtiff Product
- https://security-tracker.debian.org/tracker/CVE-2023-52355 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52355... Vendor Advisory
- https://catalog.redhat.com/software/containers/ URL
- https://bugzilla.redhat.com/show_bug.cgi?id=2251326 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:43537
- https://nvd.nist.gov/vuln/detail/CVE-2023-52355 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:49671
- https://access.redhat.com/errata/RHSA-2026:3462 Vendor Advisory
- https://access.redhat.com/downloads/content/package-browser/ URL
- https://access.redhat.com/errata/RHSA-2025:20801 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23080 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2025:21994 vendor-advisory x_refsource_REDHAT
Severity
7.5
High
CVSS 3.1: 7.5 (OSV)
CVSS 3.1: 7.5 (MITRE)
Exploitation
EPSS 2%
Type
CWE-787Out-of-bounds Write
Timeline
Published23 Aug 2026
Updated2 Sep 2026
First seen30 Mar 2026
Sources
UBUNTU-CVE-2023-52355 · OSV
CVE-2023-52355 · NVD
CVE-2023-52355 · MITRE
CVE-2023-52355 · OSV
DEBIAN-CVE-2023-52355 · OSV
Monitor software like this
Free during beta