A CVE debrief for CVE-2026-54604 was generated based on the supplied source corpus. The CVE record was published on 2026-09-17T21:17:17.000Z and has not been modified since then. OpenSlide is a C library for reading whole slide image files. A behavior change in libtiff 4.7.1 causes the indirect TIFF tile path to request a full-height destination for a partial bottom tile row, allowing uninitialized heap m [truncated]
CVE-2026-48977 OpenSlide vulnerability debrief. The OpenSlide library, used for reading whole slide image files, has a vulnerability in versions 3.4.1 to 4.0.0. This vulnerability is due to the parse_level0_xml() function in src/openslide-vendor-ventana.c, which accepts nonpositive row or column tile counts from a crafted Ventana BIF file. These invalid counts allow for attacker-controlled relative memory [truncated]