CVE-2025-9900
HIGHA flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing...
Full CISO analysis pending enrichment.
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| vLLM | pip | — | No patch |
| vLLM | pip | — | No patch |
| compat-libtiff3 | — | — | No patch |
| discovery/discovery-ui-rhel9 | — | — | No patch |
| libtiff | — | — | No patch |
| libtiff-main | — | — | No patch |
| mingw-libtiff | — | — | No patch |
| rhaiis/model-opt-cuda-rhel9 | — | — | No patch |
| spice-client-win | — | — | No patch |
How severe is it?
What is the attack surface?
What should I do?
No patch available
Monitor for updates. Consider compensating controls or temporary mitigations.
Which compliance frameworks are affected?
Compliance analysis pending. Sign in for full compliance mapping when available.
Frequently Asked Questions
What is CVE-2025-9900?
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
Is CVE-2025-9900 actively exploited?
No confirmed active exploitation of CVE-2025-9900 has been reported, but organizations should still patch proactively.
How to fix CVE-2025-9900?
No patch is currently available. Monitor vendor advisories for updates.
What is the CVSS score for CVE-2025-9900?
CVE-2025-9900 has a CVSS v3.1 base score of 8.8 (HIGH).
What are the technical details?
Original Advisory
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
Weaknesses (CWE)
CWE-123 — Write-what-where Condition: Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.
- [Architecture and Design] Use a language that provides appropriate memory abstractions.
- [Operation] Use OS-level preventative functionality integrated after the fact. Not a complete solution.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References
- access.redhat.com/errata/RHSA-2025:17651 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:17675 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:17710 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:17738 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:17739 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:17740 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:19113 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:19156 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:19276 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:19906 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:19947 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:20956 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:20998 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:21060 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:21061 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:21062 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:21407 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:21506 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:21507 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:21508 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:21994 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:23078 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:23079 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2025:23080 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:0001 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:0076 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:0077 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:0078 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:3461 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:3462 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:7504 vendor-advisory x_refsource_REDHAT
- access.redhat.com/security/cve/CVE-2025-9900 vdb-entry x_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgi issue-tracking x_refsource_REDHAT
- github.com/SexyShoelessGodofWar/LibTiff-4.7.0-Write-What-Where
- gitlab.com/libtiff/libtiff/-/issues/704
- gitlab.com/libtiff/libtiff/-/merge_requests/732
- libtiff.gitlab.io/libtiff/releases/v4.7.1.html
Timeline
Related Vulnerabilities
CVE-2024-9053 9.8 vllm: RCE via unsafe pickle deserialization in RPC server
Same package: vllm CVE-2026-25960 9.8 vllm: SSRF allows internal network access
Same package: vllm CVE-2025-47277 9.8 vLLM: RCE via exposed TCPStore in distributed inference
Same package: vllm CVE-2024-11041 9.8 vllm: RCE via unsafe pickle deserialization in MessageQueue
Same package: vllm CVE-2025-32444 9.8 vLLM: RCE via pickle deserialization on ZeroMQ
Same package: vllm