CVE-2025-61145: Double Free
Published Feb 23, 2026
·Updated
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
Affected Software
4 affected components
libtiff<=4.7.1
LibTIFF libtiff<4.7.1
Microsoft azl3 libtiff 4.6.0-11
Microsoft cbl2 libtiff 4.6.0-11
Event History
Feb 23, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:22 PM
DescriptionSeverityWeaknessAffected Software
Feb 26, 2026
Data Sourced
via Microsoft·09:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·09:01 AM
Affected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61145?
The severity of CVE-2025-61145 is classified as high due to the potential for a double free vulnerability.
2
How do I fix CVE-2025-61145?
To fix CVE-2025-61145, you should upgrade to libtiff version 4.7.2 or later where the vulnerability has been patched.
3
What components are affected by CVE-2025-61145?
CVE-2025-61145 affects the tools component, specifically tools/tiffcrop.c within libtiff versions up to and including 4.7.1.
4
Is CVE-2025-61145 a remote vulnerability?
CVE-2025-61145 is not a remote vulnerability, as it requires local access to exploit the double free condition.
5
Can CVE-2025-61145 lead to a denial of service?
Yes, exploiting CVE-2025-61145 can potentially lead to a denial of service due to memory corruption.