Skip to content

Potential signed-to-unsigned conversion in TIFF dimension parsing #24196

Description

@Ti-Mis

Description

Hi, It seemed to me that a negative signed value could potentially be converted to a large unsigned value here.

A potential signed-to-unsigned conversion issue exists in php_handle_tiff() when processing TIFF image dimensions.

The entry_value variable is declared as size_t, while the TAG_FMT_SSHORT case assigns the return value of php_ifd_get16s() to it:

case TAG_FMT_SSHORT:
entry_value = php_ifd_get16s(dir_entry+8, motorola_intel);
break;

php_ifd_get16s() returns a signed 16-bit value. Therefore, a negative value from the TIFF input can be converted to a large unsigned size_t value.

If such an entry is subsequently identified as TAG_IMAGEWIDTH or TAG_IMAGEHEIGHT, the converted value is assigned to width or height:

case TAG_IMAGEWIDTH:
case TAG_COMP_IMAGEWIDTH:
width = entry_value;
break;

case TAG_IMAGEHEIGHT:
case TAG_COMP_IMAGEHEIGHT:
height = entry_value;
break;

For example, a signed value of -1 can be converted to the maximum value of size_t instead of remaining negative.

According to the TIFF 6.0 specification, ImageWidth and ImageLength use the SHORT or LONG types, where SHORT is an unsigned 16-bit integer. The reader is expected to validate the field type.

Impact

A malformed TIFF containing a negative SSHORT value for an image dimension can therefore cause the parser to produce an unexpectedly large width or height.

Proposed solution

Validate the signed value before assigning it to the unsigned entry_value variable and reject negative values.

PHP Version

PHP 8.3.31 (CLI)

Operating System

Ubuntu 24.04

Activity

  1. Ti-Mis commented on Oct 8, 2026

    @Ti-Mis
    Author
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions