SixLabors ImageSharp TIFF Heap Out-of-Bounds Write
A heap out-of-bounds write vulnerability (CVE-2026-106118) in the SixLabors ImageSharp library allows remote attackers to cause a process crash or potentially execute arbitrary code by supplying a maliciously crafted tiled TIFF image using fax compression.
CVE search metadata
CVE search record: CVE-2026-106118. Severity: high. CVSS: 7.5. KEV: no. Product: ImageSharp (>= 3.0.0, < 4.1.1), ImageSharp (3.0.0 - 4.1.0), ImageSharp (>= 2.1.0, <= 4.1.1), ImageSharp (4.0.0-4.1.1), ImageSharp (>= 2.0.0, <= 4.1.1). Brief: SixLabors ImageSharp TIFF Heap Out-of-Bounds Write. Brief link: https://feed.craftedsignal.io/briefs/2026-10-imagesharp-tiff-oob/
What's new
- 1. added coverage for ImageSharp (>= 2.0.0, <= 4.1.1) Oct 7, 22:52 via ghsa
- 2. added coverage for ImageSharp (>= 2.0.0, <= 4.1.1) Oct 7, 22:51 via ghsa
- 3. added coverage for ImageSharp (4.0.0-4.1.1) Oct 7, 22:51 via ghsa
- 4. added coverage for ImageSharp (>= 2.1.0, <= 4.1.1) Oct 7, 22:51 via ghsa
- 5. added coverage for ImageSharp (3.0.0 - 4.1.0) Oct 7, 16:58 via ghsa
SixLabors ImageSharp, a popular cross-platform image processing library for .NET, contains a heap-based out-of-bounds write vulnerability (CVE-2026-106118) within its TIFF decoding component. The issue originates from a mismatch between buffer allocation and the fax decompressor logic when processing tiled TIFF images. Specifically, the library allocates buffers based on TileWidth, but the T4TiffCompression and T6TiffCompression decompressors incorrectly utilize the frame.Width of the full image for write operations.
This logic failure causes the decompressor to write scanline data significantly past the allocated memory boundaries. Because the write operations lack bounds checking, an attacker can control the amount of memory overwritten by crafting specific fax-compressed tiles. This defect, verified in versions 3.0.0 through 4.1.0, results in a deterministic process crash (Denial of Service) or provides a potential primitive for memory corruption and remote code execution in any application utilizing ImageSharp to process untrusted TIFF files.
Attack Chain
- Attacker crafts a malicious TIFF file with T4/T6/MH compression enabled.
- Attacker specifies an unusually high
ImageWidth(e.g., 4,000,000 pixels) while defining smallTileWidthandTileHeightdimensions (e.g., 16x16) in the TIFF header. - The victim application calls
Image.Load(stream)on the malicious TIFF file. - The library's
TiffDecoderCoredetermines the file is tiled and entersDecodeTilesChunky. - The library allocates a tile buffer sized strictly for the
TileWidth, which is significantly smaller than the logical width expected by the decompressor. - The
TiffDecompressorsFactoryincorrectly initializes the fax decompressor with the fullframe.Width. - During decompression, the
BitWriterUtilsperforms linear writes of the pixel scanlines into the undersized buffer, causing a heap memory overflow. - The process crashes due to an
AccessViolationExceptionor remains in a silent heap-corruption state depending on the pixel data content.
Impact
Successful exploitation results in an immediate Denial of Service (DoS) for the host process. Given the attacker-controllable length and width of the out-of-bounds write, this vulnerability creates a high-risk surface for potential remote code execution (RCE) in any server-side application or desktop utility that processes tiled TIFF imagery, such as image converters, web-based media upload services, or document management systems.
Recommendation
- Patch immediately by upgrading ImageSharp to version 4.1.1 or later, which addresses the incorrect decompressor width assignment and adds proper bounds checking to the write operations.
- Implement an immediate block or sanitization layer for any incoming TIFF files that exhibit unusual compression configurations (T4/T6) combined with tiled layouts until patching is completed.
- Integrate the suggested regression tests - specifically testing
Compressionmodes 2, 3, and 4 against tiled inputs withTileWidthless than the totalImageWidth- into your CI/CD pipeline to detect similar memory safety regressions.
Immediate actions
Upgrade ImageSharp to version 4.1.1 or later
Mitigations
Identify and restrict processing of tiled TIFF files in untrusted input channels
CVE-2026-106118