High severity7.5OSV Advisory· Published Aug 12, 2024· Updated Jun 17, 2026
CVE-2024-7006
CVE-2024-7006
Description
A null pointer dereference flaw was found in Libtiff via tif_dirinfo.c. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
34cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:9.2:*:*:*:*:*:*:*
- osv-coords26 versionspkg:apk/chainguard/tiffpkg:apk/chainguard/tiff-devpkg:apk/chainguard/tiff-docpkg:apk/wolfi/tiffpkg:apk/wolfi/tiff-devpkg:apk/wolfi/tiff-docpkg:rpm/almalinux/libtiffpkg:rpm/almalinux/libtiff-develpkg:rpm/almalinux/libtiff-toolspkg:rpm/opensuse/tiff&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/tiff&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/tiff&distro=openSUSE%20Leap%20Micro%205.5pkg:rpm/opensuse/tiff&distro=openSUSE%20Tumbleweedpkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Micro%206.1
< 4.7.0-r0+ 25 more
- (no CPE)range: < 4.7.0-r0
- (no CPE)range: < 4.7.0-r0
- (no CPE)range: < 4.7.0-r0
- (no CPE)range: < 4.7.0-r0
- (no CPE)range: < 4.7.0-r0
- (no CPE)range: < 4.7.0-r0
- (no CPE)range: < 4.0.9-33.el8_10
- (no CPE)range: < 4.0.9-33.el8_10
- (no CPE)range: < 4.0.9-33.el8_10
- (no CPE)range: < 4.0.9-150000.45.47.1
- (no CPE)range: < 4.6.0-150600.3.3.1
- (no CPE)range: < 4.0.9-150000.45.47.1
- (no CPE)range: < 4.6.0-5.1
- (no CPE)range: < 4.0.9-150000.45.47.1
- (no CPE)range: < 4.0.9-150000.45.47.1
- (no CPE)range: < 4.0.9-150000.45.47.1
- (no CPE)range: < 4.0.9-150000.45.47.1
- (no CPE)range: < 4.0.9-150000.45.47.1
- (no CPE)range: < 4.0.9-150000.45.47.1
- (no CPE)range: < 4.0.9-150000.45.47.1
- (no CPE)range: < 4.6.0-150600.3.3.1
- (no CPE)range: < 4.0.9-44.86.1
- (no CPE)range: < 4.0.9-44.86.1
- (no CPE)range: < 4.0.9-44.86.1
- (no CPE)range: < 4.6.0-4.1
- (no CPE)range: < 4.7.1-slfo.1.1_1.1
Patches
Vulnerability mechanics
References
7- access.redhat.com/errata/RHSA-2024:6360nvdThird Party Advisory
- access.redhat.com/security/cve/CVE-2024-7006nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
- access.redhat.com/errata/RHSA-2024:8833nvd
- access.redhat.com/errata/RHSA-2024:8914nvd
- lists.debian.org/debian-lts-announce/2025/01/msg00019.htmlnvd
- security.netapp.com/advisory/ntap-20240920-0001/nvd
News mentions
0No linked articles in our index yet.