[php-src] PR #24197: Fix signed-to-unsigned conversion in TIFF dimension parsing

From: Date: Thu, 08 Oct 2026 13:49:31 +0000
Subject: [php-src] PR #24197: Fix signed-to-unsigned conversion in TIFF dimension parsing
Groups: php.git-pulls 
Request: Send a blank email to git-pulls+get-39253@lists.php.net to get a copy of this message
Pull Request: https://github.com/php/php-src/pull/24197 Author: Ti-Mis php_handle_tiff() stores parsed TIFF values in the unsigned size_t variable entry_value. When processing TAG_FMT_SSHORT, a negative value returned by php_ifd_get16s() can be implicitly converted to a large unsigned value. If the entry represents ImageWidth or ImageHeight, this value can then be assigned to the corresponding image dimension. Solution Check the signed SHORT value before converting it to size_t. Negative values are rejected with continue, so they are not assigned to entry_value and cannot be used as image dimensions.

« previous php.git-pulls (#39253) next »