ZDI-26-529: Samsung Galaxy S25 TIFF File Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability
ZDI discloses CVE-2026-21045, a heap buffer overflow in Samsung Galaxy S25 TIFF processing enabling RCE via malicious files or pages.
ZDI-26-529 describes a heap-based buffer overflow in Samsung Galaxy S25 TIFF file processing that allows remote attackers to execute arbitrary code. User interaction is required, as the target must visit a malicious page or open a malicious file. ZDI assigned a CVSS score of 8.8, tracked as CVE-2026-21045.
USN-8755-1: libvips vulnerability
Ubuntu patches libvips flaw where crafted TIFF images converted to HEIF cause a crash, enabling denial of service.
USN-8755-1 fixes a libvips vulnerability in which specially crafted TIFF images are incorrectly handled when saved as HEIF, causing the library to crash. The impact is limited to denial of service with no code execution indicated. Ubuntu shipped updated packages.