Skip to content

IiqDecoder: bounds-check row in bad-pixel defect handling - #994

Merged
LebedevRI merged 2 commits into
darktable-org:developfrom
kalt2212:fix-iiq-badpixel-row-bounds
Oct 8, 2026
Merged

LebedevRI merged 2 commits into
darktable-org:developfrom
kalt2212:fix-iiq-badpixel-row-bounds

Conversation

@kalt2212

@kalt2212 kalt2212 commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary

Fixes a heap-buffer-overflow WRITE in the IIQ decoder's bad-pixel defect handling.

Details

PR #965 ("bounds-check col before correctBadColumn") covered the bad-column path but missed the bad-pixel path (case 129) in the same switch of correctSensorDefects(). Both are fed by the same attacker-controlled tag (IIQ 0x400 "Sensor Defects"). The code validates col but not row (uint16_t, up to 65535).

The unchecked row flows via mBadPixelPositions into transferBadPixelsToMap() (RawImage.cpp), which writes mBadPixelMap[(pitch * pos_y) + (pos_x >> 3)] guarded only by asserts — a heap OOB write in release builds, abort/DoS with asserts. Reachable by default (interpolateBadPixels=true).

PoC with ASan: exact sink replica, row=65535 → SEGV on WRITE.

Testing

ASan PoC confirms the OOB write before the fix; clean after.


AI tool use disclosure: AI was used in part for code audit and patch drafting.

PR darktable-org#965 added a bounds check for `col` in the bad-column path of
correctSensorDefects(), but the bad-pixel path (case 129) in the same
switch validates `col` and not `row`. An attacker-controlled row value
(up to 65535) flows via mBadPixelPositions into transferBadPixelsToMap,
which writes mBadPixelMap[(pitch * pos_y) + (pos_x >> 3)] guarded only
by asserts — a heap OOB write in release builds.
@kalt2212
kalt2212 requested a review from LebedevRI as a code owner October 8, 2026 20:15
Comment thread src/librawspeed/decoders/IiqDecoder.cpp
@kalt2212

kalt2212 commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Done: moved the bounds check into handleBadPixel() as suggested.

@LebedevRI
LebedevRI merged commit 6647599 into darktable-org:develop Oct 8, 2026
26 of 34 checks passed
@LebedevRI

Copy link
Copy Markdown
Member

@kalt2212 thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants