Commit b8c63871c84 for php
commit b8c63871c84cd72b8e2cac5c844605ff5f3c9f5d
Author: Daniel Scherzer <daniel.e.scherzer+phpf@gmail.com>
Date: Sun Sep 27 19:28:32 2026 -0700
ext/gd: fix undefined behavior with GD2 images with `INT_MAX`-sized chunks
Apply the changes from libgd/libgd@7ff626c48a133eff1b6608bf28b1cfae30597408 in
order to fix undefined behavior when creating a GD2 image when a compressed
chunk claims to take `INT_MAX` space.
diff --git a/ext/gd/libgd/gd_gd2.c b/ext/gd/libgd/gd_gd2.c
index 8e0307e5b12..f7e6e514915 100644
--- a/ext/gd/libgd/gd_gd2.c
+++ b/ext/gd/libgd/gd_gd2.c
@@ -164,7 +164,7 @@ static int _gd2GetHeader(gdIOCtxPtr in, int *sx, int *sy, int *cs, int *vers, in
gdFree(cidx);
goto fail1;
}
- if (cidx[i].offset < 0 || cidx[i].size < 0) {
+ if (cidx[i].offset < 0 || cidx[i].size < 0 || cidx[i].size == INT_MAX) {
gdFree(cidx);
goto fail1;
}
diff --git a/ext/gd/tests/createfromstring-overflow.phpt b/ext/gd/tests/createfromstring-overflow.phpt
new file mode 100644
index 00000000000..e79f380424e
--- /dev/null
+++ b/ext/gd/tests/createfromstring-overflow.phpt
@@ -0,0 +1,42 @@
+--TEST--
+imagecreatefromstring overflow with compressed chunk of size INT_MAX
+--EXTENSIONS--
+gd
+--FILE--
+<?php
+
+// Documentation available at https://libgd.github.io/manuals/2.3.3/files/gd_gd2-c.html
+$fileHeaderParts = [
+ "signature" => "gd2\x00",
+ "version" => "\x00\x02",
+ "width" => "\x00\x01",
+ "height" => "\x00\x01",
+ "chunk_size" => "\x00\x40",
+ "format" => "\x00\x04", // compressed truecolor image data
+ "x_chunk_count" => "\x00\x01",
+ "y_chunk_count" => "\x00\x01",
+];
+$fileHeader = implode("", $fileHeaderParts);
+
+$chunkHeaderParts = [
+ "offset" => "\x00\x00\x00\x20",
+ "size" =>"\x7F\xFF\xFF\xFF", // INT_MAX
+];
+$chunkHeader = implode("", $chunkHeaderParts);
+
+$trueColorHeaderParts = [
+ "truecolor" => "\x01",
+ "transparent" => "\x00\x00\x00\x00",
+];
+$trueColorHeader = implode("", $trueColorHeaderParts);
+
+$source = $fileHeader . $chunkHeader . $trueColorHeader;
+$img = imagecreatefromstring($source);
+var_dump($img);
+
+?>
+--EXPECTF--
+Warning: imagecreatefromstring(): Passed data is not in "GD2" format in %s on line %d
+
+Warning: imagecreatefromstring(): Couldn't create GD Image Stream out of Data in %s on line %d
+bool(false)