Description
ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When DecoderOptions.ColorProfileHandling is set to Convert, a malformed embedded profile can direct interpolation and output-LUT operations to write one float per declared channel beyond the four-float destination. This can corrupt memory and terminate the process; the default Preserve mode does not run ICC conversion. This issue is fixed in version 4.1.2.
Published: 2026-10-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Memory Corruption (potential for RCE)
Action: Upgrade
AI Analysis

Impact

The flaw exists in ImageSharp 4.0.0 through 4.1.2, where ICC LUT16 conversion can accept more than four output channels. This causes out‑of‑bounds writes to a Vector4, corrupting memory and terminating the process. A malformed embedded ICC profile can trigger the vulnerable code path when DecoderOptions.ColorProfileHandling is set to Convert.

Affected Systems

The affected product is SixLabors ImageSharp 4.0.0 to 4.1.2. The defect was fixed in release 4.1.2.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so no public exploitation is documented. However, any application that processes untrusted images could be exploited locally by providing a crafted image containing a malformed ICC profile. If the application accepts images over a network, remote exploitation becomes feasible. The bug permits an out‑of‑bounds write that could lead to memory corruption or, in the right circumstances, arbitrary code execution.

Generated by OpenCVE AI on October 6, 2026 at 19:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageSharp to version 4.1.2 or later.
  • If upgrading is not immediately possible, configure DecoderOptions.ColorProfileHandling to Preserve so that ICC conversion is disabled during image decoding.
  • Validate or strip embedded ICC profiles before passing payloads to ImageSharp to ensure no malformed profiles reach the converter.

Generated by OpenCVE AI on October 6, 2026 at 19:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When DecoderOptions.ColorProfileHandling is set to Convert, a malformed embedded profile can direct interpolation and output-LUT operations to write one float per declared channel beyond the four-float destination. This can corrupt memory and terminate the process; the default Preserve mode does not run ICC conversion. This issue is fixed in version 4.1.2.
Title ImageSharp: ICC LUT16 output channel count can write beyond Vector4
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T18:22:14.883Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106112

cve-icon Vulnrichment

Updated: 2026-10-06T18:22:10.417Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T18:16:52.810

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-106112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:00:06Z

Weaknesses