diff --git a/package/tiff/0004-fix-for-thumbnail-issue.patch b/package/tiff/0004-fix-for-thumbnail-issue.patch new file mode 100644 index 0000000000..237306f6c2 --- /dev/null +++ b/package/tiff/0004-fix-for-thumbnail-issue.patch @@ -0,0 +1,35 @@ +From e8de4dc1f923576dce9d625caeebd93f9db697e1 Mon Sep 17 00:00:00 2001 +From: Lee Howard +Date: Wed, 25 Jun 2025 17:14:18 +0000 +Subject: [PATCH] Fix for thumbnail issue #715 + +CVE: CVE-2025-8177 +Upstream: https://gitlab.com/libtiff/libtiff/-/commit/e8de4dc1f923576dce9d625caeebd93f9db697e1 +Signed-off-by: Thomas Perale +--- + tools/thumbnail.c | 10 +++++++++- + 1 file changed, 9 insertions(+), 1 deletion(-) + +diff --git a/tools/thumbnail.c b/tools/thumbnail.c +index 9cade913..7e21f521 100644 +--- a/tools/thumbnail.c ++++ b/tools/thumbnail.c +@@ -620,7 +620,15 @@ static void setrow(uint8_t *row, uint32_t nrows, const uint8_t *rows[]) + } + acc += bits[*src & mask1]; + } +- *row++ = cmap[(255 * acc) / area]; ++ if (255 * acc / area < 256) ++ { ++ *row++ = cmap[(255 * acc) / area]; ++ } ++ else ++ { ++ fprintf(stderr, "acc=%d, area=%d\n", acc, area); ++ *row++ = cmap[0]; ++ } + } + } + +-- +GitLab diff --git a/package/tiff/tiff.mk b/package/tiff/tiff.mk index bd95fdca7f..3d426fad4d 100644 --- a/package/tiff/tiff.mk +++ b/package/tiff/tiff.mk @@ -16,6 +16,9 @@ TIFF_INSTALL_STAGING = YES # 0001-don-t-skip-the-first-line-of-the-input-image.patch, 0002-fix-tiffmedian-bug.patch, 0003-conflict-resolution.patch TIFF_IGNORE_CVES += CVE-2025-8176 +# 0004-fix-for-thumbnail-issue.patch +TIFF_IGNORE_CVES += CVE-2025-8177 + # webp has a (optional) dependency on tiff, so we can't have webp # support in tiff, or that would create a circular dependency. TIFF_CONF_OPTS = \