LibTIFF 4.3.0 has an out-of-bounds read in TIFFmemcpy in tifunix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-22844.json"