OOM from malicious IFD offset in golang.org/x/image/tiff
Published Mar 25, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.39%
Description
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Affected products
-
Affected
- ≥ 0, < 0.38.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Golang.org/x/image | Golang.org/x/image/tiff | unaffected | Affected
|
No data.
Red Hat Hardened Images
golang1-25-main-1.25.9-1.hum1
Fixed · RHSA-2026:7385
Red Hat Hardened Images
golang1-26-main-1.26.2-1.hum1
Fixed · RHSA-2026:7291
Cryostat 4
cryostat/cryostat-storage-rhel9
Fix deferred
Logging Subsystem for Red Hat OpenShift
openshift-logging/cluster-logging-rhel9-operator
Fix deferred
OpenShift Service Mesh 2
openshift-golang-builder-container
Fix deferred
OpenShift Service Mesh 3
openshift-golang-builder-container
Fix deferred
Red Hat Enterprise Linux 10
golang
Fix deferred
Red Hat Enterprise Linux 8
go-toolset:rhel8/golang
Fix deferred
Red Hat Enterprise Linux 9
golang
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
golang
Fix deferred
Red Hat OpenShift Container Platform 4
openshift-golang-builder-container
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-tests-rhel9
Fix deferred
Red Hat OpenShift Virtualization 4
openshift-golang-builder-container
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | golang1-25-main-1.25.9-1.hum1 | Fixed | RHSA-2026:7385 |
| Red Hat Hardened Images | golang1-26-main-1.26.2-1.hum1 | Fixed | RHSA-2026:7291 |
| Cryostat 4 | cryostat/cryostat-storage-rhel9 | Fix deferred | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-rhel9-operator | Fix deferred | n/a |
| OpenShift Service Mesh 2 | openshift-golang-builder-container | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-golang-builder-container | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | golang | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | go-toolset:rhel8/golang | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | golang | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | golang | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift-golang-builder-container | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-tests-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Virtualization 4 | openshift-golang-builder-container | Fix deferred | n/a |
golang.org/x/image
Go
Introduced 0 Fixed 0.38.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | golang.org/x/image | 0 | 0.38.0 |
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-33809 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2451437 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-15960 Advisory
- https://github.com/advisories/GHSA-44p7-9xx4-hf2g Advisory
- https://go.dev/cl/757660 Mailing List
- https://go.dev/issue/78267 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-33809
- https://pkg.go.dev/vuln/GO-2026-4815 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-33809
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-33809 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2451437 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-15960 | Advisory | |
| https://github.com/advisories/GHSA-44p7-9xx4-hf2g | Advisory | |
| https://go.dev/cl/757660 | Mailing List | |
| https://go.dev/issue/78267 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-33809 | ||
| https://pkg.go.dev/vuln/GO-2026-4815 | Vendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2026-33809 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub