Commit 82ac0da4700 for php.net
commit 82ac0da470086295313e977c26243b2e726afd7b
Author: Ilia Alshanetsky <ilia@ilia.ws>
Date: Mon Aug 10 10:31:50 2026 -0400
Bound the HEIF meta box allocation by the file size
exif_scan_HEIF_header() allocated box.size - box_header_size with only a
lower bound, so a 37-byte file could claim a 128MB meta box and force the
allocation before any read is attempted. The second allocation in the
same block is already bounded by pos.size < ImageInfo->FileSize; apply
the same bound to the first.
Closes GH-23201
diff --git a/NEWS b/NEWS
index 299678d0a00..ffc76ae4a64 100644
--- a/NEWS
+++ b/NEWS
@@ -20,6 +20,10 @@ PHP NEWS
. Fixed bug GH-23120 (Stack overflow when comparing deeply nested DOM nodes
with DOMNode::isEqualNode()). (Weilin Du)
+- Exif:
+ . Fixed exif_read_data() allocating a HEIF meta box larger than the file
+ it came from. (iliaal)
+
- Intl:
. Fixed IntlListFormatter::__construct() leaving stale global error state
after successful calls. (Weilin Du)
diff --git a/ext/exif/exif.c b/ext/exif/exif.c
index b30644f155c..a2eb8259ac7 100644
--- a/ext/exif/exif.c
+++ b/ext/exif/exif.c
@@ -4415,7 +4415,7 @@ static bool exif_scan_HEIF_header(image_info_type *ImageInfo, unsigned char *buf
}
if (box.type == FOURCC("meta")) {
limit = box.size - box_header_size;
- if (limit < 36) {
+ if (limit < 36 || limit > ImageInfo->FileSize) {
break;
}
data = (unsigned char *)emalloc(limit);
diff --git a/ext/exif/tests/heic_meta_box_alloc.phpt b/ext/exif/tests/heic_meta_box_alloc.phpt
new file mode 100644
index 00000000000..ddc9e415b83
--- /dev/null
+++ b/ext/exif/tests/heic_meta_box_alloc.phpt
@@ -0,0 +1,23 @@
+--TEST--
+HEIC meta box size must be bounded by the file size
+--EXTENSIONS--
+exif
+--INI--
+memory_limit=32M
+--FILE--
+<?php
+// ftyp box (size 20) followed by a meta box whose size field claims 128MB,
+// in a file that is only 37 bytes. Without an upper bound the meta box
+// allocation exhausts memory_limit before any read is attempted.
+$ftyp = pack("N", 20) . "ftypheic" . str_repeat("\x00", 8);
+$meta = pack("N", 0x08000000) . "meta" . str_repeat("\x00", 8);
+file_put_contents(__DIR__."/heic_meta_box_alloc.heic", $ftyp . $meta . "\x00");
+var_dump(exif_read_data(__DIR__."/heic_meta_box_alloc.heic"));
+?>
+--CLEAN--
+<?php
+@unlink(__DIR__."/heic_meta_box_alloc.heic");
+?>
+--EXPECTF--
+Warning: exif_read_data(heic_meta_box_alloc.heic): Invalid HEIF file in %s on line %d
+bool(false)