{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/imagesharp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-106118"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ImageSharp (\u003e= 3.0.0, \u003c 4.1.1)","ImageSharp (3.0.0 - 4.1.0)","ImageSharp (\u003e= 2.1.0, \u003c= 4.1.1)","ImageSharp (4.0.0-4.1.1)","ImageSharp (\u003e= 2.0.0, \u003c= 4.1.1)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-106118","heap-overflow","imagesharp","dos","vulnerability","cve-2026-106117","image-processing","memory-corruption","cve-2026-106115","cve-2026-106112","denial-of-service","dotnet","cve-2026-106113"],"_cs_type":"advisory","_cs_vendors":["SixLabors"],"content_html":"\u003cp\u003eSixLabors ImageSharp, a popular cross-platform image processing library for .NET, contains a heap-based out-of-bounds write vulnerability (CVE-2026-106118) within its TIFF decoding component. The issue originates from a mismatch between buffer allocation and the fax decompressor logic when processing tiled TIFF images. Specifically, the library allocates buffers based on \u003ccode\u003eTileWidth\u003c/code\u003e, but the \u003ccode\u003eT4TiffCompression\u003c/code\u003e and \u003ccode\u003eT6TiffCompression\u003c/code\u003e decompressors incorrectly utilize the \u003ccode\u003eframe.Width\u003c/code\u003e of the full image for write operations.\u003c/p\u003e\n\u003cp\u003eThis logic failure causes the decompressor to write scanline data significantly past the allocated memory boundaries. Because the write operations lack bounds checking, an attacker can control the amount of memory overwritten by crafting specific fax-compressed tiles. This defect, verified in versions 3.0.0 through 4.1.0, results in a deterministic process crash (Denial of Service) or provides a potential primitive for memory corruption and remote code execution in any application utilizing ImageSharp to process untrusted TIFF files.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious TIFF file with T4/T6/MH compression enabled.\u003c/li\u003e\n\u003cli\u003eAttacker specifies an unusually high \u003ccode\u003eImageWidth\u003c/code\u003e (e.g., 4,000,000 pixels) while defining small \u003ccode\u003eTileWidth\u003c/code\u003e and \u003ccode\u003eTileHeight\u003c/code\u003e dimensions (e.g., 16x16) in the TIFF header.\u003c/li\u003e\n\u003cli\u003eThe victim application calls \u003ccode\u003eImage.Load(stream)\u003c/code\u003e on the malicious TIFF file.\u003c/li\u003e\n\u003cli\u003eThe library's \u003ccode\u003eTiffDecoderCore\u003c/code\u003e determines the file is tiled and enters \u003ccode\u003eDecodeTilesChunky\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe library allocates a tile buffer sized strictly for the \u003ccode\u003eTileWidth\u003c/code\u003e, which is significantly smaller than the logical width expected by the decompressor.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eTiffDecompressorsFactory\u003c/code\u003e incorrectly initializes the fax decompressor with the full \u003ccode\u003eframe.Width\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDuring decompression, the \u003ccode\u003eBitWriterUtils\u003c/code\u003e performs linear writes of the pixel scanlines into the undersized buffer, causing a heap memory overflow.\u003c/li\u003e\n\u003cli\u003eThe process crashes due to an \u003ccode\u003eAccessViolationException\u003c/code\u003e or remains in a silent heap-corruption state depending on the pixel data content.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate Denial of Service (DoS) for the host process. Given the attacker-controllable length and width of the out-of-bounds write, this vulnerability creates a high-risk surface for potential remote code execution (RCE) in any server-side application or desktop utility that processes tiled TIFF imagery, such as image converters, web-based media upload services, or document management systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by upgrading ImageSharp to version 4.1.1 or later, which addresses the incorrect decompressor width assignment and adds proper bounds checking to the write operations.\u003c/li\u003e\n\u003cli\u003eImplement an immediate block or sanitization layer for any incoming TIFF files that exhibit unusual compression configurations (T4/T6) combined with tiled layouts until patching is completed.\u003c/li\u003e\n\u003cli\u003eIntegrate the suggested regression tests - specifically testing \u003ccode\u003eCompression\u003c/code\u003e modes 2, 3, and 4 against tiled inputs with \u003ccode\u003eTileWidth\u003c/code\u003e less than the total \u003ccode\u003eImageWidth\u003c/code\u003e - into your CI/CD pipeline to detect similar memory safety regressions.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T22:52:55Z","date_published":"2026-10-07T16:58:35Z","id":"https://feed.craftedsignal.io/briefs/2026-10-imagesharp-tiff-oob/","summary":"A heap out-of-bounds write vulnerability (CVE-2026-106118) in the SixLabors ImageSharp library allows remote attackers to cause a process crash or potentially execute arbitrary code by supplying a maliciously crafted tiled TIFF image using fax compression.","title":"SixLabors ImageSharp TIFF Heap Out-of-Bounds Write","url":"https://feed.craftedsignal.io/briefs/2026-10-imagesharp-tiff-oob/"}],"language":"en","title":"CraftedSignal Threat Feed - Imagesharp","version":"https://jsonfeed.org/version/1.1"}