Skip to content

Validate BMP raster bounds before allocation - #19

Merged
smnandre merged 2 commits into
altophp:mainfrom
smnandre:security/bmp-raster-bounds
Sep 27, 2026
Merged

smnandre merged 2 commits into
altophp:mainfrom
smnandre:security/bmp-raster-bounds

Conversation

@smnandre

Copy link
Copy Markdown
Contributor

Raster::fromBmp() allocated pixels from unchecked BMP dimensions before applying the analyzer's 64x64 cap, and missing pixel bytes were silently interpreted as zeroes.

Validate dimensions before stride calculation or allocation, then require a complete, non-overlapping pixel payload. Preserve valid top-down and bottom-up BMP decoding.

@smnandre
smnandre force-pushed the security/bmp-raster-bounds branch from dff9d00 to 5a51d38 Compare September 27, 2026 13:17
@smnandre
smnandre merged commit e8ae177 into altophp:main Sep 27, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant