CVE-2026-106117: ImageSharp: CCITT fax decompression (T4/Modified Huffman): unbounded WriteBits overflows strip buffer — heap OOB write in SixLabors.ImageSharp
ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can pass attacker-expanded runs to BitWriterUtils.WriteBits without first checking the current row width. T4TiffCompression.WritePixelRun can accumulate oversized makeup-code runs, and ModifiedHuffmanTiffCompression.Decompress validates the width only after writing. The unchecked writes can overflow the strip buffer, corrupt heap memory, and terminate the process. This strip-path vulnerability is distinct from the tiled decompressor-width mismatch. This issue is fixed in version 4.1.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SixLabors.ImageSharpto a version that resolves this vulnerability.Fixed in 4.1.1
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using SixLabors.ImageSharp versions 3.0.0 through 4.1.0 are affected when they decode strip-based TIFF images compressed with CCITT Group 3 or Modified Huffman compression. Version 4.1.1 fixes the issue.
What does an attacker need to exploit this issue?
An attacker needs to supply a crafted strip TIFF using CCITT Group 3 or Modified Huffman compression to an application that decodes it with an affected ImageSharp version. No privileges or user interaction are required according to the provided severity vector.
What is the likely impact of processing a malicious image?
The malformed compression data can cause unchecked writes beyond the strip buffer, corrupting heap memory and terminating the process. The provided vector rates availability impact as high, with no confidentiality or integrity impact specified.