fix: use check_open(), check_compression_ratio() in all readers lacking them - #5342
Open
lgritz wants to merge 1 commit into
Open
fix: use check_open(), check_compression_ratio() in all readers lacking them#5342lgritz wants to merge 1 commit into
lgritz wants to merge 1 commit into
Conversation
Apply check_open() and/or check_compression_ratio() consistently across all the format readers that previously lacked them. This helps ensure that a small, malformed file cannot drive a large pixel allocation before any pixel data is read, or other chaos that might result from the headers claiming resolutions that the file formats themselves (or common sense) disallow. Also add a new validity test to check_open: verify that tile sizes are non-negative and not larger than the largest allowed image size for that format. Readers guarded here: cineon, dds, dpx, fits, gif, hdr, heif, ico, iff, jpeg, null, openexr (both the C++ and C-API readers), png, pnm, rla, sgi, softimage, webp, zfile. Apologies for making changes to many formats in one commit, but since the changes to the readers are short and are nearly identical, it seemed like less reviewer burden to do it all in one PR rather than breaking it up per-format. Also adds self-contained decompression-bomb / extent regression tests (targa, png-bomb, openexr-bomb, sgi, dpx, cineon, iff, webp, hdr, ico, softimage, pnm) and registers the new seed corpora with the fuzz harness. Assisted-by: GitHub Copilot / Claude Opus 4.8 Signed-off-by: Larry Gritz <lg@larrygritz.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Apply check_open() and check_compression_ratio() consistently across all the format readers that previously lacked them. This helps ensure that a small, malformed file cannot drive a large pixel allocation before any pixel data is read, or other chaos that might result from the headers claiming resolutions that the file formats themselves (or common sense) disallow.
Also add a new validity test to check_open: verify that tile sizes are non-negative and not larger than the largest allowed image size for that format.
Readers guarded here: cineon, dds, dpx, fits, gif, hdr, heif, ico, iff, jpeg, null, openexr (both the C++ and C-API readers), png, pnm, rla, sgi, softimage, webp, zfile.
Apologies for making changes to many formats in one commit, but since the changes to the readers are short and are nearly identical, it seemed like less reviewer burden to do it all in one PR rather than breaking it up per-format.
Also adds a whole bunch of self-contained decompression-bomb / extent regression tests (targa, png-bomb, openexr-bomb, sgi, dpx, cineon, iff, webp, hdr, ico, softimage, pnm) and registers the new seed corpora with the fuzz harness.
Fixes #3974
Assisted-by: GitHub Copilot / Claude Opus 4.8