Description
ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, tiled TIFF decoding allocates a destination buffer using TileWidth but TiffDecompressorsFactory.Create constructs T4, T6, and Modified Huffman decompressors using the full frame width. TiffDecoderCore.DecodeTilesChunky can therefore direct frame-width fax scanlines into a tile-width buffer when TileWidth is smaller than ImageWidth. The mismatch causes attacker-controlled out-of-bounds writes, heap corruption, and process termination even with legal per-row run codes. This tiled-path vulnerability is distinct from oversized CCITT runs in strip decoding. This issue is fixed in version 4.1.1.
Published: 2026-10-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Heap corruption and process termination due to out‑of‑bounds writes in TIFF decoding
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises when the tiled TIFF decoder allocates a buffer sized by the tile width but the fax decompressor writes full‑width scanlines into it. This mismatch enables an out‑of‑bounds write that corrupts heap memory and can cause the host process to crash. The issue is limited to the tile decoding path for T4, T6, and Modified Huffman fax decompression and does not involve any memory control or privilege escalation beyond the corruption.

Affected Systems

The flaw affects the SixLabors:ImageSharp library in releases from 3.0.0 up to and including 4.1.1. Versions 4.1.1 and newer contain the fix, rendering the library safe against this specific bug.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. The likely attack vector is the processing of a malicious TIFF image by any application that uses the vulnerable ImageSharp library. Absent public exploits, the exploitation risk appears moderate, but the heap‑corruption nature warrants prompt remediation.

Generated by OpenCVE AI on October 6, 2026 at 20:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SixLabors:ImageSharp to version 4.1.1 or later.
  • If an upgrade is not immediately possible, disable T4, T6, and Modified Huffman decoding for untrusted TIFF files or restrict processing to trusted image sources.
  • Add a pre‑decoding check to reject TIFF files whose tile width is smaller than the image width.

Generated by OpenCVE AI on October 6, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, tiled TIFF decoding allocates a destination buffer using TileWidth but TiffDecompressorsFactory.Create constructs T4, T6, and Modified Huffman decompressors using the full frame width. TiffDecoderCore.DecodeTilesChunky can therefore direct frame-width fax scanlines into a tile-width buffer when TileWidth is smaller than ImageWidth. The mismatch causes attacker-controlled out-of-bounds writes, heap corruption, and process termination even with legal per-row run codes. This tiled-path vulnerability is distinct from oversized CCITT runs in strip decoding. This issue is fixed in version 4.1.1.
Title ImageSharp: Tiled fax TIFF: tile buffer sized by TileWidth but fax decompressor writes scanlines of ImageWidth — heap OOB write
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T19:29:39.226Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106118

cve-icon Vulnrichment

Updated: 2026-10-06T19:27:53.040Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:42.640

Modified: 2026-10-06T20:17:17.703

Link: CVE-2026-106118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:45:06Z

Weaknesses