CVE-2025-8176: LibTIFF tiffmedian.c get_histogram use after free
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function gethistogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.
Other sources
LibTIFF tiffmedian.c gethistogram use after free
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LibTIFFto a version that resolves this vulnerability.Patch fe10872e53efba9cc36c66ac4ab3b41a839d5172
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8176?
CVE-2025-8176 is classified as a critical severity vulnerability.
How do I fix CVE-2025-8176?
To fix CVE-2025-8176, update LibTIFF to version 4.7.1 or later.
What type of vulnerability is CVE-2025-8176?
CVE-2025-8176 is a use after free vulnerability affecting the get_histogram function.
Which versions of LibTIFF are affected by CVE-2025-8176?
CVE-2025-8176 affects LibTIFF versions up to and including 4.7.0.
Is CVE-2025-8176 exploitable remotely?
CVE-2025-8176 requires local access for exploitation.