#1147247 tiff: 1 unresolved CVE in Debian Trixie (1 Critical)

Package:
tiff
Source:
tiff
Submitter:
Samonte, Joshua
Date:
2026-09-10 15:29:03 UTC
Severity:
normal
Tags:
#1147247#5
Date:
2026-09-10 03:14:06 UTC
From:
To:
Hi Team,

I am reporting an unresolved CVE affecting the tiff source package (specifically flagging libtiff6, libtiff-dev, and libtiffxx6 binary packages) on Debian Trixie (Debian 13), identified via a Prisma scanner.


  *   CVE-2026-52490 (Critical)

Notes:
The vulnerable code (tiffcrop.c, process_command_opts()) belongs to libtiff-tools. While we don't install the tools binary, the library versions are still flagged due to the shared source version.

This is already fixed upstream (v4.7.2rc2) and is present in Debian unstable (4.7.2-1). Could you advise on when this fix is expected to transition into Trixie?


Regards,
Joshua Aldwin L. Samonte
Software Prod & Plat Eng Specialist
Advanced Technology Centers in the Philippines
*: joshua.a.samonte@accenture.com<mailto:joshua.a.samonte@accenture.com>