[php-src] PR #24197: Fix signed-to-unsigned conversion in TIFF dimension parsing
| From: | Ti-Mis | Date: | Thu, 08 Oct 2026 13:49:31 +0000 |
| Subject: | [php-src] PR #24197: Fix signed-to-unsigned conversion in TIFF dimension parsing | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39253@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24197
Author: Ti-Mis
php_handle_tiff() stores parsed TIFF values in the unsigned size_t variable entry_value. When
processing TAG_FMT_SSHORT, a negative value returned by php_ifd_get16s() can be implicitly converted
to a large unsigned value.
If the entry represents ImageWidth or ImageHeight, this value can then be assigned to the
corresponding image dimension.
Solution
Check the signed SHORT value before converting it to size_t. Negative values are rejected with
continue, so they are not assigned to entry_value and cannot be used as image dimensions.