Skip to content

Fix signed-to-unsigned conversion in TIFF dimension parsing - #24197

Open
Ti-Mis wants to merge 1 commit into
php:masterfrom
Ti-Mis:STBU-image.c
Open

Ti-Mis wants to merge 1 commit into
php:masterfrom
Ti-Mis:STBU-image.c

Conversation

@Ti-Mis

@Ti-Mis Ti-Mis commented Oct 8, 2026

Copy link
Copy Markdown

php_handle_tiff() stores parsed TIFF values in the unsigned size_t variable entry_value. When processing TAG_FMT_SSHORT, a negative value returned by php_ifd_get16s() can be implicitly converted to a large unsigned value.

If the entry represents ImageWidth or ImageHeight, this value can then be assigned to the corresponding image dimension.

Solution

Check the signed SHORT value before converting it to size_t. Negative values are rejected with continue, so they are not assigned to entry_value and cannot be used as image dimensions.

Problem:
Potential conversion of a negative signed TIFF value to a large unsigned value when parsing image dimensions.

Solution: Reject negative signed SHORT values before assigning them to the unsigned entry_value variable.

Signed-off-by: Timofey Mishin <t.mishin@fobos-nt.ru>
Signed-off-by: Georgij Tsarin <crystarm@altlinux.org>
@ArtUkrainskiy

Copy link
Copy Markdown
Contributor

These values only end up in the array getimagesize() returns; nothing allocates or indexes by them, so a negative SSHORT in a malformed file gives a nonsense dimension, not a memory issue. TAG_FMT_SLONG has the same conversion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants