Impact
The vulnerability arises when the tiled TIFF decoder allocates a buffer sized by the tile width but the fax decompressor writes full‑width scanlines into it. This mismatch enables an out‑of‑bounds write that corrupts heap memory and can cause the host process to crash. The issue is limited to the tile decoding path for T4, T6, and Modified Huffman fax decompression and does not involve any memory control or privilege escalation beyond the corruption.
Affected Systems
The flaw affects the SixLabors:ImageSharp library in releases from 3.0.0 up to and including 4.1.1. Versions 4.1.1 and newer contain the fix, rendering the library safe against this specific bug.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. The likely attack vector is the processing of a malicious TIFF image by any application that uses the vulnerable ImageSharp library. Absent public exploits, the exploitation risk appears moderate, but the heap‑corruption nature warrants prompt remediation.
OpenCVE Enrichment