CVE-2025-61143: Null Pointer Dereference
Published Feb 23, 2026
·Updated
libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
Affected Software
4 affected componentsFixes available
libtiff<=4.7.1
LibTIFF libtiff<4.7.1
Microsoft cbl2 libtiff 4.6.0-11
Microsoft azl3 libtiff 4.6.0-11
Event History
Feb 23, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:22 PM
DescriptionSeverityWeaknessAffected Software
Feb 26, 2026
Data Sourced
via Microsoft·09:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·09:01 AM
Affected Software
Updated
via Microsoft·09:01 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-61143?
CVE-2025-61143 has been rated as a moderate severity vulnerability due to the potential for application crashes.
2
How do I fix CVE-2025-61143?
To fix CVE-2025-61143, update to libtiff version 4.7.2 or later where the issue has been patched.
3
Which versions of libtiff are affected by CVE-2025-61143?
CVE-2025-61143 affects libtiff versions up to and including 4.7.1.
4
What type of vulnerability is CVE-2025-61143?
CVE-2025-61143 is classified as a NULL pointer dereference vulnerability.
5
What are the potential consequences of CVE-2025-61143?
Exploitation of CVE-2025-61143 may lead to crashes or denial of service in applications using affected versions of libtiff.