[Git][security-tracker-team/security-tracker][master] Add CVE-2026-52491/tiff

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 15:10:16 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
41f686ed by Salvatore Bonaccorso at 2026-08-26T16:09:40+02:00
Add CVE-2026-52491/tiff

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1315,7 +1315,8 @@ CVE-2026-53965 (The MCP PHP SDK (Composer package mcp/sdk) is the official Model
 CVE-2026-52776 (Compliance-trestle (Trestle) is a tooling platform for managing compli ...)
 	NOT-FOR-US: compliance-trestle
 CVE-2026-52491 (An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an ...)
-	TODO: check
+	- tiff 4.7.2-1
+	NOTE: Fixed by: https://gitlab.com/libtiff/libtiff/-/commit/9ce4d089bcf25496663776d9e6336738112f09a3 (v4.7.2rc2)
 CVE-2026-52489 (Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de ...)
 	- gpac <removed>
 	[bullseye] - gpac <end-of-life> (EOL in bullseye LTS)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/41f686ed64fa7473a7497d61cae0a74056392784

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/41f686ed64fa7473a7497d61cae0a74056392784
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/a07ea75c/attachment.htm>


More information about the debian-security-tracker-commits mailing list