Impact
The flaw exists in ImageSharp 4.0.0 through 4.1.2, where ICC LUT16 conversion can accept more than four output channels. This causes out‑of‑bounds writes to a Vector4, corrupting memory and terminating the process. A malformed embedded ICC profile can trigger the vulnerable code path when DecoderOptions.ColorProfileHandling is set to Convert.
Affected Systems
The affected product is SixLabors ImageSharp 4.0.0 to 4.1.2. The defect was fixed in release 4.1.2.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so no public exploitation is documented. However, any application that processes untrusted images could be exploited locally by providing a crafted image containing a malformed ICC profile. If the application accepts images over a network, remote exploitation becomes feasible. The bug permits an out‑of‑bounds write that could lead to memory corruption or, in the right circumstances, arbitrary code execution.
OpenCVE Enrichment