Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.0

libtiff May Cause Data Loss Due to Double Free Error

CVE-2025-61145
Summary

The libtiff library contains a double free error in the tiffcrop.c component. This error could potentially lead to data loss or crashes if a malicious file is processed by the library. System administrators should upgrade to a patched version of libtiff.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
libtiff libtiff <= 4.7.1 –
Original title
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
Original description
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
nvd CVSS3.1 5.0
Vulnerability type
CWE-415
Published: 23 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026