Sceawere

Vulnerability Detail

CVE-2026-106117UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ImageSharp Heap Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
7h ago
Vendor
SixLabors
Product
ImageSharp
Attack Type
CWE-787: Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can pass attacker-expanded runs to BitWriterUtils.WriteBits without first checking the current row width. T4TiffCompression.WritePixelRun can accumulate oversized makeup-code runs, and ModifiedHuffmanTiffCompression.Decompress validates the width only after writing. The unchecked writes can overflow the strip buffer, corrupt heap memory, and terminate the process. This strip-path vulnerability is distinct from the tiled decompressor-width mismatch. This issue is fixed in version 4.1.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-06T18:16:53.550Z",
  "pubdate": "2026-10-06T18:16:53.550Z",
  "executiveSummary": "ImageSharp versions 3.0.0 through 4.1.1 are susceptible to a heap-based buffer overflow vulnerability during the processing of TIFF images using CCITT Group 3 or Modified Huffman compression.\nThe vulnerability arises from insufficient boundary validation when decoding pixel runs, allowing an attacker to supply crafted image data that forces the application to write data beyond the allocated memory buffer.\nThis memory corruption can lead to application crashes, potential arbitrary code execution, or denial of service (DoS) conditions.\nThe flaw specifically affects the strip-path decompression logic, distinguishing it from previously documented tiled-path vulnerabilities.\nAttackers can trigger this vulnerability by providing a malicious TIFF file that, upon processing, overflows the strip buffer.\nDue to the nature of graphics processing, this poses a significant risk to any system or service that automatically parses or manipulates user-provided image files, such as image hosting platforms or web-based editors.\nUsers are strongly advised to upgrade to version 4.1.1 or later to remediate the flaw.",
  "technicalDetails": "The vulnerability is located within the TIFF decompression logic of the ImageSharp library, specifically affecting the handling of CCITT Group 3 and Modified Huffman compressed data.\nThe root cause is a lack of rigorous bounds checking before data is written to the heap-allocated strip buffer. During the decompression process, the functions T4TiffCompression.WritePixelRun and ModifiedHuffmanTiffCompression.Decompress fail to validate the cumulative width of pixel runs against the designated row dimensions before invoking BitWriterUtils.WriteBits.\nIn the case of T4TiffCompression.WritePixelRun, the routine can accumulate oversized 'makeup-code' runs without ensuring the total pixel count stays within the row's constraints. Similarly, ModifiedHuffmanTiffCompression.Decompress defers width validation until after the writing operation has already commenced. Because the validation logic occurs post-write, an attacker can manipulate the compressed bitstream to specify a sequence of runs that exceed the expected row length.\nWhen BitWriterUtils.WriteBits is passed these attacker-expanded runs, it proceeds to perform write operations based on the malformed metadata. Since the destination strip buffer has a fixed size based on legitimate image dimensions, the oversized data writes beyond the buffer boundary, resulting in a heap buffer overflow.\nThe exploitation flow involves the following steps: 1) The attacker constructs a malformed TIFF image file containing specifically crafted CCITT or Huffman compressed streams. 2) The victim application loads this image, triggering the affected decompression path. 3) The parser interprets the malicious makeup-codes, leading to an calculation of an excessive pixel width. 4) The library attempts to write these pixels into a pre-allocated heap buffer. 5) Due to the absence of active bounds enforcement, the buffer is overwritten, leading to memory corruption. 6) This corruption can be leveraged to corrupt surrounding memory structures, potentially hijacking control flow or forcing the process to terminate via a segmentation fault.\nThis strip-path vulnerability is architecturally distinct from the tiled-path width-mismatch issue. The vulnerability is present in versions 3.0.0 to 4.1.0 and is successfully mitigated in 4.1.1 through the implementation of strict pre-write boundary checks."
}
CVE-2026-106117: ImageSharp Heap Buffer Overflow (HIGH Severity, CVSS: 7.5) | Sceawere