PatchSiren cyber security CVE debrief
CVE-2016-9448 Libtiff CVE debrief
CVE-2016-9448 is a denial-of-service vulnerability in libtiff’s TIFFFetchNormalTag parsing path. A crafted TIFF can trigger a NULL pointer dereference and crash when the code handles TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII values that access 0-byte arrays. The issue was described as an incomplete fix for CVE-2016-9297, so systems that only partially remediated the earlier bug may still be exposed.
- Vendor
- Libtiff
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Teams that process untrusted TIFF files with libtiff, including application owners, distribution maintainers, and vendors shipping libtiff 4.0.6 or affected downstream packages. Services that accept user-uploaded images should treat this as a priority availability issue.
Technical summary
NVD lists CVE-2016-9448 with CVSS v3.0 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and CWE-476. The vulnerable behavior is in TIFFFetchNormalTag, where specific tag types (TIFF_SETGET_C16ASCII and TIFF_SETGET_C32_ASCII) can lead to access of 0-byte arrays and a NULL pointer dereference, resulting in a crash rather than code execution. The corpus indicates libtiff 4.0.6 as vulnerable, and NVD also lists an affected openSUSE 13.2 package.
Defensive priority
High
Recommended defensive actions
- Upgrade libtiff to a version that includes the complete fix for CVE-2016-9448 and the earlier CVE-2016-9297 issue.
- Rebuild or update any downstream packages and images that bundle libtiff, including distro packages and embedded copies.
- Prioritize patching systems that parse user-supplied TIFF content, especially upload pipelines and image-processing services.
- Add crash monitoring and service restart handling for components that depend on libtiff while remediation is underway.
- Review whether your current libtiff version traces back to a partial fix for CVE-2016-9297 and verify vendor advisories for your distribution.
Evidence notes
All claims are grounded in the supplied NVD record, the CVE description, and the linked advisories. The corpus explicitly states the NULL pointer dereference, the affected tag types, the 0-byte array condition, and the relationship to CVE-2016-9297. The timeline reflects the CVE publication date of 2017-01-27; later record modification on 2026-05-13 is a metadata update, not the vulnerability date.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9448 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9448
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9448 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9448
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201701-16
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.