<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>ImageSharp (&gt;= 3.0.0, &lt; 4.1.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/imagesharp--3.0.0--4.1.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:58:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/imagesharp--3.0.0--4.1.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SixLabors ImageSharp TIFF Heap Out-of-Bounds Write</title><link>https://feed.craftedsignal.io/briefs/2026-10-imagesharp-tiff-oob/</link><pubDate>Wed, 07 Oct 2026 16:58:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-imagesharp-tiff-oob/</guid><description>A heap out-of-bounds write vulnerability (CVE-2026-106118) in the SixLabors ImageSharp library allows remote attackers to cause a process crash or potentially execute arbitrary code by supplying a maliciously crafted tiled TIFF image using fax compression.</description><content:encoded><![CDATA[<p>SixLabors ImageSharp, a popular cross-platform image processing library for .NET, contains a heap-based out-of-bounds write vulnerability (CVE-2026-106118) within its TIFF decoding component. The issue originates from a mismatch between buffer allocation and the fax decompressor logic when processing tiled TIFF images. Specifically, the library allocates buffers based on <code>TileWidth</code>, but the <code>T4TiffCompression</code> and <code>T6TiffCompression</code> decompressors incorrectly utilize the <code>frame.Width</code> of the full image for write operations.</p>
<p>This logic failure causes the decompressor to write scanline data significantly past the allocated memory boundaries. Because the write operations lack bounds checking, an attacker can control the amount of memory overwritten by crafting specific fax-compressed tiles. This defect, verified in versions 3.0.0 through 4.1.0, results in a deterministic process crash (Denial of Service) or provides a potential primitive for memory corruption and remote code execution in any application utilizing ImageSharp to process untrusted TIFF files.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts a malicious TIFF file with T4/T6/MH compression enabled.</li>
<li>Attacker specifies an unusually high <code>ImageWidth</code> (e.g., 4,000,000 pixels) while defining small <code>TileWidth</code> and <code>TileHeight</code> dimensions (e.g., 16x16) in the TIFF header.</li>
<li>The victim application calls <code>Image.Load(stream)</code> on the malicious TIFF file.</li>
<li>The library's <code>TiffDecoderCore</code> determines the file is tiled and enters <code>DecodeTilesChunky</code>.</li>
<li>The library allocates a tile buffer sized strictly for the <code>TileWidth</code>, which is significantly smaller than the logical width expected by the decompressor.</li>
<li>The <code>TiffDecompressorsFactory</code> incorrectly initializes the fax decompressor with the full <code>frame.Width</code>.</li>
<li>During decompression, the <code>BitWriterUtils</code> performs linear writes of the pixel scanlines into the undersized buffer, causing a heap memory overflow.</li>
<li>The process crashes due to an <code>AccessViolationException</code> or remains in a silent heap-corruption state depending on the pixel data content.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in an immediate Denial of Service (DoS) for the host process. Given the attacker-controllable length and width of the out-of-bounds write, this vulnerability creates a high-risk surface for potential remote code execution (RCE) in any server-side application or desktop utility that processes tiled TIFF imagery, such as image converters, web-based media upload services, or document management systems.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch immediately by upgrading ImageSharp to version 4.1.1 or later, which addresses the incorrect decompressor width assignment and adds proper bounds checking to the write operations.</li>
<li>Implement an immediate block or sanitization layer for any incoming TIFF files that exhibit unusual compression configurations (T4/T6) combined with tiled layouts until patching is completed.</li>
<li>Integrate the suggested regression tests - specifically testing <code>Compression</code> modes 2, 3, and 4 against tiled inputs with <code>TileWidth</code> less than the total <code>ImageWidth</code> - into your CI/CD pipeline to detect similar memory safety regressions.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve-2026-106118</category><category>heap-overflow</category><category>imagesharp</category><category>dos</category><category>vulnerability</category><category>cve-2026-106117</category><category>image-processing</category><category>memory-corruption</category><category>cve-2026-106115</category><category>cve-2026-106112</category><category>denial-of-service</category><category>dotnet</category><category>cve-2026-106113</category></item></channel></rss>