{"id":"UBUNTU-CVE-2025-9165","details":"A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because \"this is a memory leak on a command line tool that is about to exit anyway\". In the reply the project maintainer declares this issue as \"a simple 'bug' when leaving the command line tool and (...) not a security issue at all\".","modified":"2026-01-30T00:51:00.696414Z","published":"2025-08-19T20:15:00Z","related":["USN-7783-1"],"upstream":["CVE-2025-9165"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-9165"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-9165"},{"type":"REPORT","url":"https://drive.google.com/file/d/1FWhmkzksH8-qU0ZM6seBzGNB3aPnX3G8/view?usp=sharing"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.320543"},{"type":"REPORT","url":"https://vuldb.com/?id.320543"},{"type":"REPORT","url":"https://vuldb.com/?submit.630506"},{"type":"REPORT","url":"https://vuldb.com/?submit.630507"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7783-1"}],"affected":[{"package":{"name":"gdal","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/gdal@1.10.1+dfsg-5ubuntu1+esm1?arch=source&distro=esm-infra-legacy/trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.0-3.1ubuntu4","1.9.0-3.1ubuntu6","1.10.1+dfsg-2","1.10.1+dfsg-2build1","1.10.1+dfsg-3","1.10.1+dfsg-3build1","1.10.1+dfsg-3build2","1.10.1+dfsg-3ubuntu1","1.10.1+dfsg-3ubuntu2","1.10.1+dfsg-5ubuntu1","1.10.1+dfsg-5ubuntu1+esm1"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"1.10.1+dfsg-5ubuntu1+esm1","binary_name":"gdal-bin"},{"binary_version":"1.10.1+dfsg-5ubuntu1+esm1","binary_name":"libgdal-dev"},{"binary_version":"1.10.1+dfsg-5ubuntu1+esm1","binary_name":"libgdal-java"},{"binary_version":"1.10.1+dfsg-5ubuntu1+esm1","binary_name":"libgdal-perl"},{"binary_version":"1.10.1+dfsg-5ubuntu1+esm1","binary_name":"libgdal1-dev"},{"binary_version":"1.10.1+dfsg-5ubuntu1+esm1","binary_name":"libgdal1h"},{"binary_version":"1.10.1+dfsg-5ubuntu1+esm1","binary_name":"python-gdal"},{"binary_version":"1.10.1+dfsg-5ubuntu1+esm1","binary_name":"python3-gdal"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"tiff","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/tiff@4.0.3-7ubuntu0.11+esm16?arch=source&distro=esm-infra-legacy/trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.3-7ubuntu0.11+esm16"}]}],"versions":["4.0.2-4ubuntu3","4.0.3-5ubuntu1","4.0.3-6","4.0.3-6ubuntu1","4.0.3-7","4.0.3-7ubuntu0.1","4.0.3-7ubuntu0.2","4.0.3-7ubuntu0.3","4.0.3-7ubuntu0.4","4.0.3-7ubuntu0.6","4.0.3-7ubuntu0.7","4.0.3-7ubuntu0.8","4.0.3-7ubuntu0.9","4.0.3-7ubuntu0.10","4.0.3-7ubuntu0.11","4.0.3-7ubuntu0.11+esm1","4.0.3-7ubuntu0.11+esm2","4.0.3-7ubuntu0.11+esm3","4.0.3-7ubuntu0.11+esm4","4.0.3-7ubuntu0.11+esm5","4.0.3-7ubuntu0.11+esm6","4.0.3-7ubuntu0.11+esm7","4.0.3-7ubuntu0.11+esm8","4.0.3-7ubuntu0.11+esm9","4.0.3-7ubuntu0.11+esm10","4.0.3-7ubuntu0.11+esm11","4.0.3-7ubuntu0.11+esm12","4.0.3-7ubuntu0.11+esm13","4.0.3-7ubuntu0.11+esm14","4.0.3-7ubuntu0.11+esm15"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"4.0.3-7ubuntu0.11+esm16","binary_name":"libtiff-opengl"},{"binary_version":"4.0.3-7ubuntu0.11+esm16","binary_name":"libtiff-tools"},{"binary_version":"4.0.3-7ubuntu0.11+esm16","binary_name":"libtiff4-dev"},{"binary_version":"4.0.3-7ubuntu0.11+esm16","binary_name":"libtiff5"},{"binary_version":"4.0.3-7ubuntu0.11+esm16","binary_name":"libtiff5-alt-dev"},{"binary_version":"4.0.3-7ubuntu0.11+esm16","binary_name":"libtiff5-dev"},{"binary_version":"4.0.3-7ubuntu0.11+esm16","binary_name":"libtiffxx5"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"tiff","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/tiff@4.0.6-1ubuntu0.8+esm19?arch=source&distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.6-1ubuntu0.8+esm19"}]}],"versions":["4.0.3-12.3ubuntu2","4.0.5-1","4.0.6-1","4.0.6-1ubuntu0.1","4.0.6-1ubuntu0.2","4.0.6-1ubuntu0.3","4.0.6-1ubuntu0.4","4.0.6-1ubuntu0.5","4.0.6-1ubuntu0.6","4.0.6-1ubuntu0.7","4.0.6-1ubuntu0.8","4.0.6-1ubuntu0.8+esm1","4.0.6-1ubuntu0.8+esm2","4.0.6-1ubuntu0.8+esm3","4.0.6-1ubuntu0.8+esm4","4.0.6-1ubuntu0.8+esm6","4.0.6-1ubuntu0.8+esm7","4.0.6-1ubuntu0.8+esm8","4.0.6-1ubuntu0.8+esm9","4.0.6-1ubuntu0.8+esm10","4.0.6-1ubuntu0.8+esm11","4.0.6-1ubuntu0.8+esm12","4.0.6-1ubuntu0.8+esm13","4.0.6-1ubuntu0.8+esm14","4.0.6-1ubuntu0.8+esm15","4.0.6-1ubuntu0.8+esm16","4.0.6-1ubuntu0.8+esm17","4.0.6-1ubuntu0.8+esm18"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"4.0.6-1ubuntu0.8+esm19","binary_name":"libtiff-opengl"},{"binary_version":"4.0.6-1ubuntu0.8+esm19","binary_name":"libtiff-tools"},{"binary_version":"4.0.6-1ubuntu0.8+esm19","binary_name":"libtiff5"},{"binary_version":"4.0.6-1ubuntu0.8+esm19","binary_name":"libtiff5-dev"},{"binary_version":"4.0.6-1ubuntu0.8+esm19","binary_name":"libtiffxx5"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"gdal","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/gdal@1.11.3+dfsg-3build2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.11.2+dfsg-3ubuntu3","1.11.2+dfsg-3ubuntu4","1.11.3+dfsg-2build1","1.11.3+dfsg-2build2","1.11.3+dfsg-2build3","1.11.3+dfsg-3","1.11.3+dfsg-3build1","1.11.3+dfsg-3build2"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"1.11.3+dfsg-3build2","binary_name":"gdal-bin"},{"binary_version":"1.11.3+dfsg-3build2","binary_name":"libgdal-dev"},{"binary_version":"1.11.3+dfsg-3build2","binary_name":"libgdal-java"},{"binary_version":"1.11.3+dfsg-3build2","binary_name":"libgdal-perl"},{"binary_version":"1.11.3+dfsg-3build2","binary_name":"libgdal1-dev"},{"binary_version":"1.11.3+dfsg-3build2","binary_name":"libgdal1i"},{"binary_version":"1.11.3+dfsg-3build2","binary_name":"python-gdal"},{"binary_version":"1.11.3+dfsg-3build2","binary_name":"python3-gdal"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"texmaker","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/texmaker@4.4.1-1.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.4.1-1","4.4.1-1.1"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"4.4.1-1.1","binary_name":"texmaker"},{"binary_version":"4.4.1-1.1","binary_name":"texmaker-data"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"tiff","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/tiff@4.0.9-5ubuntu0.10+esm9?arch=source&distro=esm-infra/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.9-5ubuntu0.10+esm9"}]}],"versions":["4.0.8-5","4.0.8-6","4.0.9-1","4.0.9-2","4.0.9-3","4.0.9-4","4.0.9-4ubuntu1","4.0.9-5","4.0.9-5ubuntu0.1","4.0.9-5ubuntu0.2","4.0.9-5ubuntu0.3","4.0.9-5ubuntu0.4","4.0.9-5ubuntu0.5","4.0.9-5ubuntu0.6","4.0.9-5ubuntu0.7","4.0.9-5ubuntu0.8","4.0.9-5ubuntu0.9","4.0.9-5ubuntu0.10","4.0.9-5ubuntu0.10+esm1","4.0.9-5ubuntu0.10+esm2","4.0.9-5ubuntu0.10+esm3","4.0.9-5ubuntu0.10+esm4","4.0.9-5ubuntu0.10+esm5","4.0.9-5ubuntu0.10+esm6","4.0.9-5ubuntu0.10+esm7","4.0.9-5ubuntu0.10+esm8"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"4.0.9-5ubuntu0.10+esm9","binary_name":"libtiff-dev"},{"binary_version":"4.0.9-5ubuntu0.10+esm9","binary_name":"libtiff-opengl"},{"binary_version":"4.0.9-5ubuntu0.10+esm9","binary_name":"libtiff-tools"},{"binary_version":"4.0.9-5ubuntu0.10+esm9","binary_name":"libtiff5"},{"binary_version":"4.0.9-5ubuntu0.10+esm9","binary_name":"libtiff5-dev"},{"binary_version":"4.0.9-5ubuntu0.10+esm9","binary_name":"libtiffxx5"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"neuron","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/neuron@7.5-1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.5-1"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"7.5-1","binary_name":"neuron"},{"binary_version":"7.5-1","binary_name":"neuron-dev"},{"binary_version":"7.5-1","binary_name":"python3-neuron"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"qtwebengine-opensource-src","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/qtwebengine-opensource-src@5.9.5+dfsg-0ubuntu2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.9.1+dfsg-4","5.9.1+dfsg-4ubuntu1","5.9.2+dfsg-2ubuntu1","5.9.3+dfsg-0ubuntu1","5.9.4+dfsg-0ubuntu1","5.9.5+dfsg-0ubuntu2"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"5.9.5+dfsg-0ubuntu2","binary_name":"libqt5webengine-data"},{"binary_version":"5.9.5+dfsg-0ubuntu2","binary_name":"libqt5webengine5"},{"binary_version":"5.9.5+dfsg-0ubuntu2","binary_name":"libqt5webenginecore5"},{"binary_version":"5.9.5+dfsg-0ubuntu2","binary_name":"libqt5webenginewidgets5"},{"binary_version":"5.9.5+dfsg-0ubuntu2","binary_name":"qml-module-qtwebengine"},{"binary_version":"5.9.5+dfsg-0ubuntu2","binary_name":"qtwebengine5-dev"},{"binary_version":"5.9.5+dfsg-0ubuntu2","binary_name":"qtwebengine5-dev-tools"},{"binary_version":"5.9.5+dfsg-0ubuntu2","binary_name":"qtwebengine5-doc-html"},{"binary_version":"5.9.5+dfsg-0ubuntu2","binary_name":"qtwebengine5-examples"},{"binary_version":"5.9.5+dfsg-0ubuntu2","binary_name":"qtwebengine5-private-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"texmaker","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/texmaker@5.0.2-1build2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.5-1","5.0.2-1","5.0.2-1build1","5.0.2-1build2"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"5.0.2-1build2","binary_name":"texmaker"},{"binary_version":"5.0.2-1build2","binary_name":"texmaker-data"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"tiff","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/tiff@4.1.0+git191117-2ubuntu0.20.04.14+esm2?arch=source&distro=esm-infra/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.0+git191117-2ubuntu0.20.04.14+esm2"}]}],"versions":["4.0.10+git191003-1","4.1.0+git191117-1","4.1.0+git191117-2","4.1.0+git191117-2build1","4.1.0+git191117-2ubuntu0.20.04.1","4.1.0+git191117-2ubuntu0.20.04.2","4.1.0+git191117-2ubuntu0.20.04.3","4.1.0+git191117-2ubuntu0.20.04.4","4.1.0+git191117-2ubuntu0.20.04.5","4.1.0+git191117-2ubuntu0.20.04.6","4.1.0+git191117-2ubuntu0.20.04.7","4.1.0+git191117-2ubuntu0.20.04.8","4.1.0+git191117-2ubuntu0.20.04.9","4.1.0+git191117-2ubuntu0.20.04.10","4.1.0+git191117-2ubuntu0.20.04.11","4.1.0+git191117-2ubuntu0.20.04.12","4.1.0+git191117-2ubuntu0.20.04.13","4.1.0+git191117-2ubuntu0.20.04.14","4.1.0+git191117-2ubuntu0.20.04.14+esm1"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"4.1.0+git191117-2ubuntu0.20.04.14+esm2","binary_name":"libtiff-dev"},{"binary_version":"4.1.0+git191117-2ubuntu0.20.04.14+esm2","binary_name":"libtiff-opengl"},{"binary_version":"4.1.0+git191117-2ubuntu0.20.04.14+esm2","binary_name":"libtiff-tools"},{"binary_version":"4.1.0+git191117-2ubuntu0.20.04.14+esm2","binary_name":"libtiff5"},{"binary_version":"4.1.0+git191117-2ubuntu0.20.04.14+esm2","binary_name":"libtiff5-dev"},{"binary_version":"4.1.0+git191117-2ubuntu0.20.04.14+esm2","binary_name":"libtiffxx5"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"neuron","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/neuron@7.6.3-1build4?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.6.3-1build2","7.6.3-1build3","7.6.3-1build4"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"7.6.3-1build4","binary_name":"neuron"},{"binary_version":"7.6.3-1build4","binary_name":"neuron-dev"},{"binary_version":"7.6.3-1build4","binary_name":"python3-neuron"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"qtwebengine-opensource-src","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/qtwebengine-opensource-src@5.12.8+dfsg-0ubuntu1.1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.12.4+dfsg-1ubuntu1","5.12.4+dfsg-1ubuntu3","5.12.5+dfsg-3ubuntu1","5.12.5+dfsg-6ubuntu2","5.12.5+dfsg-7","5.12.5+dfsg-7build1","5.12.8+dfsg-0ubuntu1","5.12.8+dfsg-0ubuntu1.1"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"5.12.8+dfsg-0ubuntu1.1","binary_name":"libqt5webengine-data"},{"binary_version":"5.12.8+dfsg-0ubuntu1.1","binary_name":"libqt5webengine5"},{"binary_version":"5.12.8+dfsg-0ubuntu1.1","binary_name":"libqt5webenginecore5"},{"binary_version":"5.12.8+dfsg-0ubuntu1.1","binary_name":"libqt5webenginewidgets5"},{"binary_version":"5.12.8+dfsg-0ubuntu1.1","binary_name":"qml-module-qtwebengine"},{"binary_version":"5.12.8+dfsg-0ubuntu1.1","binary_name":"qtwebengine5-dev"},{"binary_version":"5.12.8+dfsg-0ubuntu1.1","binary_name":"qtwebengine5-dev-tools"},{"binary_version":"5.12.8+dfsg-0ubuntu1.1","binary_name":"qtwebengine5-doc-html"},{"binary_version":"5.12.8+dfsg-0ubuntu1.1","binary_name":"qtwebengine5-examples"},{"binary_version":"5.12.8+dfsg-0ubuntu1.1","binary_name":"qtwebengine5-private-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"texmaker","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/texmaker@5.0.3-1build5?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.3-1build2","5.0.3-1build3","5.0.3-1build4","5.0.3-1build5"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"5.0.3-1build5","binary_name":"texmaker"},{"binary_version":"5.0.3-1build5","binary_name":"texmaker-data"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"neuron","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/neuron@7.6.3-1build6?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.6.3-1build5","7.6.3-1build6"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"7.6.3-1build6","binary_name":"neuron"},{"binary_version":"7.6.3-1build6","binary_name":"neuron-dev"},{"binary_version":"7.6.3-1build6","binary_name":"python3-neuron"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"qtwebengine-opensource-src","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/qtwebengine-opensource-src@5.15.9+dfsg-1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.15.6+dfsg-1","5.15.6+dfsg-2","5.15.7+dfsg-2","5.15.8+dfsg-1","5.15.8+dfsg-1build1","5.15.8+dfsg-1build2","5.15.8+dfsg-2","5.15.9+dfsg-1"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"5.15.9+dfsg-1","binary_name":"libqt5pdf5"},{"binary_version":"5.15.9+dfsg-1","binary_name":"libqt5pdfwidgets5"},{"binary_version":"5.15.9+dfsg-1","binary_name":"libqt5webengine-data"},{"binary_version":"5.15.9+dfsg-1","binary_name":"libqt5webengine5"},{"binary_version":"5.15.9+dfsg-1","binary_name":"libqt5webenginecore5"},{"binary_version":"5.15.9+dfsg-1","binary_name":"libqt5webenginewidgets5"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qml-module-qtquick-pdf"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qml-module-qtwebengine"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qt5-image-formats-plugin-pdf"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qtpdf5-dev"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qtpdf5-doc-html"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qtpdf5-examples"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qtwebengine5-dev"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qtwebengine5-dev-tools"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qtwebengine5-doc-html"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qtwebengine5-examples"},{"binary_version":"5.15.9+dfsg-1","binary_name":"qtwebengine5-private-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"texmaker","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/texmaker@5.0.3-1build9?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.3-1build8","5.0.3-1build9"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"5.0.3-1build9","binary_name":"texmaker"},{"binary_version":"5.0.3-1build9","binary_name":"texmaker-data"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"tiff","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/tiff@4.3.0-6ubuntu0.12?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.0-6ubuntu0.12"}]}],"versions":["4.3.0-1","4.3.0-2","4.3.0-3","4.3.0-3build1","4.3.0-4","4.3.0-5","4.3.0-6","4.3.0-6ubuntu0.1","4.3.0-6ubuntu0.2","4.3.0-6ubuntu0.3","4.3.0-6ubuntu0.4","4.3.0-6ubuntu0.5","4.3.0-6ubuntu0.6","4.3.0-6ubuntu0.7","4.3.0-6ubuntu0.8","4.3.0-6ubuntu0.9","4.3.0-6ubuntu0.10","4.3.0-6ubuntu0.11"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"4.3.0-6ubuntu0.12","binary_name":"libtiff-dev"},{"binary_version":"4.3.0-6ubuntu0.12","binary_name":"libtiff-opengl"},{"binary_version":"4.3.0-6ubuntu0.12","binary_name":"libtiff-tools"},{"binary_version":"4.3.0-6ubuntu0.12","binary_name":"libtiff5"},{"binary_version":"4.3.0-6ubuntu0.12","binary_name":"libtiff5-dev"},{"binary_version":"4.3.0-6ubuntu0.12","binary_name":"libtiffxx5"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"qtwebengine-opensource-src","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/qtwebengine-opensource-src@5.15.16+dfsg-3?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.15.15+dfsg-2","5.15.15+dfsg-2build2","5.15.15+dfsg-2ubuntu1","5.15.16+dfsg-1","5.15.16+dfsg-1ubuntu2","5.15.16+dfsg-1ubuntu4","5.15.16+dfsg-3"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"5.15.16+dfsg-3","binary_name":"libqt5pdf5"},{"binary_version":"5.15.16+dfsg-3","binary_name":"libqt5pdfwidgets5"},{"binary_version":"5.15.16+dfsg-3","binary_name":"libqt5webengine-data"},{"binary_version":"5.15.16+dfsg-3","binary_name":"libqt5webengine5"},{"binary_version":"5.15.16+dfsg-3","binary_name":"libqt5webenginecore5"},{"binary_version":"5.15.16+dfsg-3","binary_name":"libqt5webenginewidgets5"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qml-module-qtquick-pdf"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qml-module-qtwebengine"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qt5-image-formats-plugin-pdf"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qtpdf5-dev"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qtpdf5-doc-html"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qtpdf5-examples"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qtwebengine5-dev"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qtwebengine5-dev-tools"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qtwebengine5-doc-html"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qtwebengine5-examples"},{"binary_version":"5.15.16+dfsg-3","binary_name":"qtwebengine5-private-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"texmaker","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/texmaker@5.1.3+dfsg-1build8?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.1.3+dfsg-1build4","5.1.3+dfsg-1build5","5.1.3+dfsg-1build6","5.1.3+dfsg-1build7","5.1.3+dfsg-1build8"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"5.1.3+dfsg-1build8","binary_name":"texmaker"},{"binary_version":"5.1.3+dfsg-1build8","binary_name":"texmaker-data"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"tiff","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/tiff@4.5.1+git230720-4ubuntu2.4?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.5.1+git230720-4ubuntu2.4"}]}],"versions":["4.5.1+git230720-1ubuntu1","4.5.1+git230720-3ubuntu1","4.5.1+git230720-4ubuntu1","4.5.1+git230720-4ubuntu2","4.5.1+git230720-4ubuntu2.1","4.5.1+git230720-4ubuntu2.2","4.5.1+git230720-4ubuntu2.3"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"4.5.1+git230720-4ubuntu2.4","binary_name":"libtiff-dev"},{"binary_version":"4.5.1+git230720-4ubuntu2.4","binary_name":"libtiff-opengl"},{"binary_version":"4.5.1+git230720-4ubuntu2.4","binary_name":"libtiff-tools"},{"binary_version":"4.5.1+git230720-4ubuntu2.4","binary_name":"libtiff5-dev"},{"binary_version":"4.5.1+git230720-4ubuntu2.4","binary_name":"libtiff6"},{"binary_version":"4.5.1+git230720-4ubuntu2.4","binary_name":"libtiffxx6"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"qtwebengine-opensource-src","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/qtwebengine-opensource-src@5.15.19+dfsg2-1?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.15.18+dfsg-2","5.15.18+dfsg-2build1","5.15.19+dfsg-1","5.15.19+dfsg2-1"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"5.15.19+dfsg2-1","binary_name":"libqt5pdf5"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"libqt5pdfwidgets5"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"libqt5webengine-data"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"libqt5webengine5"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"libqt5webenginecore5"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"libqt5webenginewidgets5"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qml-module-qtquick-pdf"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qml-module-qtwebengine"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qt5-image-formats-plugin-pdf"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qtpdf5-dev"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qtpdf5-doc-html"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qtpdf5-examples"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qtwebengine5-dev"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qtwebengine5-dev-tools"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qtwebengine5-doc-html"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qtwebengine5-examples"},{"binary_version":"5.15.19+dfsg2-1","binary_name":"qtwebengine5-private-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"texmaker","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/texmaker@5.1.3+dfsg-3build1?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.1.3+dfsg-3","5.1.3+dfsg-3build1"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"5.1.3+dfsg-3build1","binary_name":"texmaker"},{"binary_version":"5.1.3+dfsg-3build1","binary_name":"texmaker-data"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}},{"package":{"name":"tiff","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/tiff@4.7.0-3ubuntu3?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.0-3ubuntu3"}]}],"versions":["4.5.1+git230720-4ubuntu4","4.7.0-3ubuntu1","4.7.0-3ubuntu2"],"ecosystem_specific":{"priority_reason":"Only a memory leak in a command line tool","binaries":[{"binary_version":"4.7.0-3ubuntu3","binary_name":"libtiff-dev"},{"binary_version":"4.7.0-3ubuntu3","binary_name":"libtiff-opengl"},{"binary_version":"4.7.0-3ubuntu3","binary_name":"libtiff-tools"},{"binary_version":"4.7.0-3ubuntu3","binary_name":"libtiff5-dev"},{"binary_version":"4.7.0-3ubuntu3","binary_name":"libtiff6"},{"binary_version":"4.7.0-3ubuntu3","binary_name":"libtiffxx6"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9165.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"},{"type":"Ubuntu","score":"low"}]}