Skip to content
Red HatCVE-2026-18495

Red Hat Ceph Storage 4: buffer overflow

Medium6.1CVE-2026-18495 · Published Sep 11, 2026 · updated Sep 16, 2026

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Ceph Storage 4
Product
all versionsNo fix yet
Red Hat Ceph Storage 6
Product
all versionsNo fix yet
Red Hat Ceph Storage 7
Product
all versionsNo fix yet
Red Hat Ceph Storage 8
Product
all versionsNo fix yet
Red Hat Ceph Storage 9
Product
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux 10: denial of service
Medium6.2Sep 11
Red Hat Dynamic Client Registration service of Keycloak: information disclosure
Medium4.9Sep 11
A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost
Medium5.5Sep 11
Red Hat, Inc.: CVE: user could modify a managed cluster’s ManagedClusterAddOn
High7.7Sep 11
Red Hat GStreamer: integer overflow
Medium4.4Sep 11
Red Hat admin backend of gvfs: race condition
High7.0Sep 10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.