PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106112 SixLabors CVE debrief

A memory corruption vulnerability exists in ImageSharp when ICC conversion is enabled and a malformed embedded ICC LUT16 profile with more than four output channels is processed. The ICC parser accepts up to 15 CLUT output channels, while the conversion implementation stores intermediate values in `Vector4`. Affected versions include 4.0.0, 4.1.0, and 4.1.1 of the `SixLabors.ImageSharp` NuGet package.

Vendor
SixLabors
Product
SixLabors.ImageSharp
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for systems using ImageSharp for ICC conversion should assess exposure and verify the integrity of color profiles. This includes operators, platform administrators, vulnerability management teams, and security teams who need to prioritize verifying exposure in systems using ImageSharp for ICC conversion and assessing the integrity of color profiles due to a memory corruption vulnerability.

Why it matters

Defenders should prioritize verifying exposure in systems using ImageSharp for ICC conversion and assessing the integrity of color profiles due to a memory corruption vulnerability.

  • Potential memory corruption during ICC conversion
  • Verification of color profile integrity is necessary
  • Upgrade to version 4.1.2 or later to address the vulnerability

Technical summary

The ICC parser in ImageSharp accepts up to 15 CLUT output channels, but the conversion implementation stores intermediate values in `Vector4`, which can lead to memory corruption when processing malformed ICC LUT16 profiles. Affected versions include 4.0.0, 4.1.0, and 4.1.1 of the `SixLabors.ImageSharp` NuGet package. This vulnerability can be triggered by a malformed embedded ICC LUT16 profile with more than four output channels, potentially causing memory corruption during ICC conversion in ImageSharp. Defenders should prioritize verifying exposure in systems using ImageSharp for ICC conversion and assessing the integrity of color profiles.

Defensive priority

Defenders should prioritize verifying exposure in systems using ImageSharp for ICC conversion and assessing the integrity of color profiles.

Recommended defensive actions

  • Verify the version of SixLabors.ImageSharp in use and upgrade to 4.1.2 or later if necessary.
  • Assess the integrity of color profiles used in ImageSharp ICC conversion.
  • Monitor systems using ImageSharp for ICC conversion for potential memory corruption.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability was reproduced in the `ColorProfileHandling.Convert` path with an attacker-controlled profile declaring three input channels and fifteen output channels. This issue arises from the ICC parser accepting up to 15 CLUT output channels, while the conversion implementation stores intermediate values in `Vector4`, potentially leading to memory corruption. Defenders should verify the integrity of color profiles used in ImageSharp ICC conversion and assess exposure in systems using ImageSharp for ICC conversion.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106112 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106112

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106112 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106112

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • ImageSharp: ICC LUT16 output channel count can write beyond Vector4

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/NuGet/GHSA-ffp7-56pq-64mr.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-ffp7-56pq-64mr

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/pull/3187

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/commit/b03f0ed7e5be760eecc740fa53dd166b18ae9b23

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.