Impact
A bug in ImageSharp’s ExifReader.ReadValues64 trusts the 64‑bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, the reader returns without advancing the stream or breaking the outer loop, which can cause a decoder thread to execute for an attacker‑controlled duration. This loop consumes CPU and keeps a worker thread busy, creating a resource exhaustion condition that can degrade or deny service. The weakness is identified as CWE‑835, an infinite loop flaw.
Affected Systems
SixLabors ImageSharp libraries from version 2.0.0 through 4.1.1 are affected. Applications that process TIFF or BigTIFF files containing Exif metadata and rely on these ImageSharp releases are vulnerable. The issue is fixed in ImageSharp version 4.1.2 and later.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate impact. No EPSS data is available, and the vulnerability is not currently listed in CISA’s KEV catalog. An attacker who can supply a crafted BigTIFF file can cause a decoder thread to enter a non‑progressing loop, which may be executed over the network if the application accepts user‑uploaded images or locally if untrusted files are read. The likely attack vector is inferred to be remote via image upload, but the vulnerability can also be triggered by local file usage. The attack requires that the vulnerable library parse the file, so the practical exploitation vector is likely remote via image upload but local file usage is also possible.
OpenCVE Enrichment