Sceawere
Vulnerability Detail
CVE-2026-106112UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ImageSharp Memory Corruption Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 7h ago
- Vendor
- SixLabors
- Product
- ImageSharp
- Attack Type
- CWE-787: Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When DecoderOptions.ColorProfileHandling is set to Convert, a malformed embedded profile can direct interpolation and output-LUT operations to write one float per declared channel beyond the four-float destination. This can corrupt memory and terminate the process; the default Preserve mode does not run ICC conversion. This issue is fixed in version 4.1.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T18:16:52.810Z",
"pubdate": "2026-10-06T18:16:52.810Z",
"executiveSummary": "ImageSharp versions 4.0.0 through 4.1.2 contain a critical memory corruption vulnerability stemming from improper input validation within the ICC profile conversion logic. The issue specifically resides in the handling of LUT16 (Look-Up Table) conversions when DecoderOptions.ColorProfileHandling is explicitly configured to 'Convert'.\nAn attacker can craft a malformed ICC profile with an excessive number of output channels, exceeding the storage capacity of the internal Vector4 structure. By triggering this conversion, the process attempts to perform out-of-bounds writes into memory adjacent to the allocated buffer. This leads to heap or stack corruption, likely resulting in a denial-of-service (process termination) or potential arbitrary code execution depending on the memory layout and environment protections.\nThis vulnerability is reachable only when the non-default 'Convert' profile handling mode is active, as the default 'Preserve' mode bypasses the vulnerable ICC conversion logic. The flaw represents a significant risk to applications processing untrusted image data, requiring an update to version 4.1.2 or later to eliminate the underlying architectural defect.",
"technicalDetails": "The vulnerability originates in the ICC LUT16 conversion pipeline, specifically within the interaction between ClutCalculator.Calculate and LutEntryCalculator.CalculateLut. These components are hardcoded to utilize the Vector4 structure—a data type designed to hold exactly four floating-point values—to store intermediate calculation results and final output vectors.\nThe root cause is an insufficient bounds check during the parsing of ICC profile color spaces. When an image is processed with DecoderOptions.ColorProfileHandling set to 'Convert', the library attempts to map the embedded ICC profile's color channels to the output destination. If a malicious ICC profile declares a color space with more than four output channels, the library fails to restrict the channel count to the Vector4 capacity.\nThe exploitation flow proceeds as follows: First, an attacker supplies an image containing a maliciously crafted ICC profile. Second, the victim application processes this image with the configuration option 'Convert' enabled. Third, during the execution of the interpolation and output-LUT operations, the code iterates through the declared output channels of the profile. Fourth, because the destination buffer is constrained by Vector4, but the logic relies on the channel count provided by the malformed profile, the write operations proceed beyond the four-float limit. This results in an out-of-bounds memory write, where subsequent floats are written to unintended memory addresses.\nThis memory corruption occurs within the context of the processing thread. Since the writes occur outside the allocated memory space for the output vector, the operation effectively overwrites adjacent metadata, pointers, or stack-frame information. In modern runtime environments, this typically triggers an immediate access violation or segmentation fault, terminating the process and resulting in a denial-of-service. In specific heap-spraying or sophisticated exploitation scenarios, such primitives can potentially be leveraged to divert the control flow of the application.\nThe vulnerability affects ImageSharp versions 4.0.0 up to 4.1.2. The flaw is not present in versions where ColorProfileHandling is set to the default 'Preserve' mode, as the problematic conversion logic is never invoked. The issue was rectified in version 4.1.2 by implementing rigorous validation of the channel count against the target data structure constraints."
}