在 libtiff 中发现了一个缺陷。 工具中存在一个堆缓冲区溢出漏洞,这是由于在处理特制的 BigTIFF 文件时发生的整数截断错误。攻击者可以提供一个特制的 BigTIFF 文件,导致 64 位的 值被截断为 32 位整数。这会导致内存分配不足,并随后引发越界内存复制,最终造成程序崩溃和严重的内存损坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Hardened Images | 4.7.2-2.hum1 ~ * |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Ceph Storage 4 | - |
cpe:/a:redhat:ceph_storage:4
|
|
| Red Hat | Red Hat Ceph Storage 6 | - |
cpe:/a:redhat:ceph_storage:6
|
|
| Red Hat | Red Hat Ceph Storage 7 | - |
cpe:/a:redhat:ceph_storage:7
|
|
| Red Hat | Red Hat Ceph Storage 8 | - |
cpe:/a:redhat:ceph_storage:8
|
|
| Red Hat | Red Hat Ceph Storage 9 | - |
cpe:/a:redhat:ceph_storage:9
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89060 | 7.7 HIGH | Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multiclu |
| CVE-2026-89329 | 6.2 MEDIUM | Device-mapper-multipath: local denial of service via blocking ipc send operations |
| CVE-2026-77159 | 5.5 MEDIUM | Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership chan |
| CVE-2026-89298 | 4.9 MEDIUM | Keycloak-services: keycloak-services: confidential client secret disclosed to view-clients |
| CVE-2026-88914 | 4.4 MEDIUM | Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea |
No comments yet