PT-2026-106829 · Unknown · Imagesharp
CVE-2026-106112
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ImageSharp versions 4.0.0 through 4.1.1
Description
An issue exists in the ICC LUT16 conversion process where the system accepts more than four output channels, despite
ClutCalculator.Calculate() and LutEntryCalculator.CalculateLut() storing values in Vector4. When DecoderOptions.ColorProfileHandling is set to Convert, a malformed embedded profile can cause interpolation and output-LUT operations to write data beyond the four-float destination, leading to memory corruption and process termination. This does not occur in the default Preserve mode.Recommendations
Update to version 4.1.2.
Avoid setting
DecoderOptions.ColorProfileHandling to Convert when processing untrusted profiles.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imagesharp