CVE-2025-8961

low
Published 2025-08-14 · Modified 2026-04-29
CVSS v3
3.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS v2
1.7
VIR risk
3.3

Description

A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.

Predictions

Exploit likelihood
34%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-8961

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-8961.html

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://gitlab.com/libtiff/libtiff/-/issues/721#note_2670686960

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://gitlab.com/libtiff/libtiff/-/issues/721

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed4.7.0-5
debian debiansidfixed4.7.0-5
debian debiantrixiefixed4.7.0-3+deb13u1

Application impact

VendorProductVersionsFixed
libtifflibtiff4.7.0

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.