Out-of-bounds read In sixlabors.imagesharp
Description
ImageSharp: ICC LUT16 output channel count can write beyond Vector4
Summary
When ICC conversion is enabled, a malformed embedded ICC LUT16 profile with
more than four output channels can corrupt memory during ImageSharp color
conversion. The ICC parser accepts up to 15 CLUT output channels, while the
conversion implementation stores intermediate values in Vector4.
Affected package and versions
Package: SixLabors.ImageSharp (NuGet)
Affected published releases: 4.0.0, 4.1.0, and 4.1.1
Affected range: >= 4.0.0, <= 4.1.1
Commit 0815358f9202a78bc7f3b83e19282dc3654b500f corresponds to release v4.1.1.
The reproduced ColorProfileHandling.Convert path and the unsafe Vector4 LUT operations are present in v4.0.0 and unchanged through v4.1.1. The three-output control succeeds on all three published 4.x releases; the fifteen-output exploit terminates all three.
Details
IccClut accepts one through fifteen input and output channels. In the
reproduced A2B0 LUT16 path, an attacker-controlled profile declares three
input channels and fifteen output channels. ClutCalculator.Calculate
passes a pointer to a four-float Vector4 result into interpolation code that
writes one float per declared output channel. It consequently writes fifteen
floats. The same LUT16 tag also has fifteen output LUTs; their
LutEntryCalculator.CalculateLut
implementation uses Unsafe.Add from the first float of a four-float Vector4.
An application reaches this code by decoding an image containing the profile
with DecoderOptions.ColorProfileHandling set to Convert. Preserve is the
default and does not run ICC conversion.
Reproduction environment and result
The supplied exploit and control were run against the published NuGet 4.1.1
net8.0 DLL in Docker on Debian 12 / Linux arm64 with .NET SDK 8.0.424 and
.NET runtime 8.0.30.
The control changes only the declared output-channel count from fifteen to three and completes successfully. The exploit terminates with exit status 139 before it reaches the completion marker. This runtime PoC establishes memory corruption in the combined LUT16 CLUT/output-LUT path; it does not isolate which unsafe write first corrupts the stack. The full self-contained Docker PoC is included below.
Complete control output:
mode=control output_channels=3 imagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll imagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f png_bytes=204 decode_completed Docker exit status: 0
Complete exploit output:
mode=exploit output_channels=15 imagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll imagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f png_bytes=207 Docker exit status: 139
No active exploitation is known.
Impact
Applications that enable ICC conversion while processing attacker-supplied images can be made to terminate through memory corruption in the reproduced LUT16 CLUT/output-LUT path. This report is limited to output-channel counts greater than four in that path; it does not claim a TRC issue or other unreproduced ICC paths.
Complete PoC files
Program.cs:
using System; using System.Buffers.Binary; using System.IO; using System.Reflection; using System.Text; using SixLabors.ImageSharp; using SixLabors.ImageSharp.Formats; using SixLabors.ImageSharp.Metadata.Profiles.Icc;...
Project file:
<Project Sdk="Microsoft.NET.Sdk"> <PropertyGroup> <OutputType>Exe</OutputType> <TargetFramework>net8.0</TargetFramework> <ImplicitUsings>disable</ImplicitUsings> <Nullable>enable</Nullable> </PropertyGroup> <ItemGroup>...
Dockerfile:
FROM mcr.microsoft.com/dotnet/sdk:8.0 WORKDIR /work COPY ffp7.csproj Program.cs ./ # direct DLL reference so ImageSharp's package build target is not invoked. RUN printf '%s\n' '<Project Sdk="Microsoft.NET.Sdk"><PropertyGroup><TargetFramework>net8.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include="SixLabors.ImageSharp" Version="4.1.1" /></ItemGroup></Project>' > fetch.csproj \ && dotnet restore fetch.csproj --nologo \ && rm fetch.csproj \ && dotnet build ffp7.csproj -c Release --nologo -v quiet...
Run:
docker build -t imagesharp-ffp7-poc . docker run --rm imagesharp-ffp7-poc control docker run --rm imagesharp-ffp7-poc exploit
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
nuget | 4.1.2 |
Aliases
References