CVE Vulnerabilities

CVE-2025-9900

Write-what-where Condition

Published: Sep 23, 2025 | Modified: Jan 06, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

A flaw was found in Libtiff. This vulnerability is a write-what-where condition, triggered when the library processes a specially crafted TIFF image file.

By providing an abnormally large image height value in the files metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

Weakness

Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatlibtiff-0:4.6.0-6.el10_0.1*
Red Hat Enterprise Linux 10RedHatlibtiff-0:4.6.0-6.el10_1.1*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatcompat-libtiff3-0:3.9.4-12.el7_9.1*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatlibtiff-0:4.0.3-35.el7_9.1*
Red Hat Enterprise Linux 8RedHatcompat-libtiff3-0:3.9.4-14.el8_10*
Red Hat Enterprise Linux 8RedHatlibtiff-0:4.0.9-35.el8_10*
Red Hat Enterprise Linux 8RedHatmingw-libtiff-0:4.0.9-3.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatcompat-libtiff3-0:3.9.4-13.el8_2.1*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatlibtiff-0:4.0.9-17.el8_2.1*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatspice-client-win-0:8.10-3.el8_2.1*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatcompat-libtiff3-0:3.9.4-13.el8_4.1*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatlibtiff-0:4.0.9-18.el8_4.1*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatspice-client-win-0:8.10-3.el8_4.1*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatcompat-libtiff3-0:3.9.4-13.el8_4.1*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatlibtiff-0:4.0.9-18.el8_4.1*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatspice-client-win-0:8.10-3.el8_4.1*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatcompat-libtiff3-0:3.9.4-13.el8_6.1*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatlibtiff-0:4.0.9-21.el8_6.1*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatspice-client-win-0:8.10-3.el8_6.1*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatcompat-libtiff3-0:3.9.4-13.el8_6.1*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatlibtiff-0:4.0.9-21.el8_6.1*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatspice-client-win-0:8.10-3.el8_6.1*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatcompat-libtiff3-0:3.9.4-13.el8_6.1*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatlibtiff-0:4.0.9-21.el8_6.1*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatspice-client-win-0:8.10-3.el8_6.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatcompat-libtiff3-0:3.9.4-13.el8_8.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatlibtiff-0:4.0.9-29.el8_8.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatspice-client-win-0:8.10-3.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatcompat-libtiff3-0:3.9.4-13.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatlibtiff-0:4.0.9-29.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatspice-client-win-0:8.10-3.el8_8.1*
Red Hat Enterprise Linux 9RedHatlibtiff-0:4.4.0-13.el9_6.2*
Red Hat Enterprise Linux 9RedHatlibtiff-0:4.4.0-15.el9_7.2*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatlibtiff-0:4.2.0-3.el9_0.2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatlibtiff-0:4.4.0-8.el9_2.4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatlibtiff-0:4.4.0-12.el9_4.4*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-cuda-rhel9:sha256:ec961e5acfde5c1ad0a7e0e2c86a0bf56b9bc46357fa124f9db6dff1006076ab*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-rocm-rhel9:sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57*
Red Hat AI Inference Server 3.2RedHatrhaiis/model-opt-cuda-rhel9:sha256:14e32e88f1b89f59ed34a6d712746b82a6a54c6ed4727784f18aeff853abbdc7*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:sha256:69cb9c84b806ee2f448bdbbcf3174855432f5caec8f31ca2a345655da4a72f57*
GdalUbuntuesm-apps/xenial*
GdalUbuntuesm-infra-legacy/trusty*
Qtwebengine-opensource-srcUbuntudevel*
Qtwebengine-opensource-srcUbuntuesm-apps/bionic*
Qtwebengine-opensource-srcUbuntuesm-apps/focal*
Qtwebengine-opensource-srcUbuntuesm-apps/jammy*
Qtwebengine-opensource-srcUbuntuesm-apps/noble*
Qtwebengine-opensource-srcUbuntujammy*
Qtwebengine-opensource-srcUbuntunoble*
Qtwebengine-opensource-srcUbuntuplucky*
Qtwebengine-opensource-srcUbuntuquesting*
TexmakerUbuntuesm-apps/bionic*
TexmakerUbuntuesm-apps/focal*
TexmakerUbuntuesm-apps/jammy*
TexmakerUbuntuesm-apps/noble*
TexmakerUbuntujammy*
TexmakerUbuntunoble*
TexmakerUbuntuplucky*
TexmakerUbuntuquesting*
TiffUbuntudevel*
TiffUbuntuesm-infra-legacy/trusty*
TiffUbuntuesm-infra/bionic*
TiffUbuntuesm-infra/focal*
TiffUbuntuesm-infra/xenial*
TiffUbuntujammy*
TiffUbuntunoble*
TiffUbuntuplucky*
TiffUbuntuquesting*

Potential Mitigations

References