LibTIFF 4.3.0 has an out-of-bounds read in TIFFmemcpy in tifunix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-8514.json"