Commit 65a194836 for imagemagick.org

commit 65a19483668525a3dca05376b8efbcb1fe28506a
Author: Acts1631 <69813585+acts-1631@users.noreply.github.com>
Date:   Tue Sep 29 11:38:10 2026 -0400

    Limit C2PA manifest resource use (#8980)

    The C2PA decoder reads delegate-generated JSON with no size limit.
    It also leaves that file in temporary storage. Large or repeated
    manifest outputs can consume excessive memory and disk.

    Apply the existing profile size limit before reading the manifest and
    remove the JSON file on every exit path.

diff --git a/coders/c2pa.c b/coders/c2pa.c
index 58fd55b4c..1d3c1ec38 100644
--- a/coders/c2pa.c
+++ b/coders/c2pa.c
@@ -108,6 +108,9 @@ static Image *ReadC2PAImage(const ImageInfo *image_info,
   MagickBooleanType
     status;

+  struct stat
+    attributes;
+
   /*
     Open image file.
   */
@@ -140,7 +143,10 @@ static Image *ReadC2PAImage(const ImageInfo *image_info,
   read_info=DestroyImageInfo(read_info);
   image=DestroyImageList(image);
   if (status == MagickFalse)
-    return((Image *) NULL);
+    {
+      (void) RelinquishUniqueFileResource(json_filename);
+      return((Image *) NULL);
+    }
   /*
     Read image.
   */
@@ -150,8 +156,22 @@ static Image *ReadC2PAImage(const ImageInfo *image_info,
   image=ReadImage(read_info,exception);
   read_info=DestroyImageInfo(read_info);
   if (image == (Image *) NULL)
-    return(image);
-  json=FileToString(json_filename,~0UL,exception);
+    {
+      (void) RelinquishUniqueFileResource(json_filename);
+      return(image);
+    }
+  if ((GetPathAttributes(json_filename,&attributes) != MagickFalse) &&
+      ((attributes.st_size < 0) || ((MagickSizeType) attributes.st_size >
+      GetMaxProfileSize())))
+    {
+      (void) ThrowMagickException(exception,GetMagickModule(),
+        ResourceLimitWarning,"ProfileSizeExceedsLimit","`%llu'",
+        (unsigned long long) attributes.st_size);
+      (void) RelinquishUniqueFileResource(json_filename);
+      return(image);
+    }
+  json=FileToString(json_filename,GetMaxProfileSize(),exception);
+  (void) RelinquishUniqueFileResource(json_filename);
   if (json == (char *) NULL)
     return(image);
   (void) SetImageProperty(image,"c2pa:manifest",json,exception);