All of lore.kernel.org
 help / color / mirror / Atom feed
From: Peter Korsgaard <peter@korsgaard.com>
To: buildroot@buildroot.org
Cc: Grzegorz Blach <grzegorz@blach.pl>
Subject: [Buildroot] [PATCH 2/2] package/graphicsmagick: add post-1.3.45 security fixes
Date: Wed, 23 Apr 2025 21:06:43 +0200	[thread overview]
Message-ID: <20250423190643.3526208-2-peter@korsgaard.com> (raw)
In-Reply-To: <20250423190643.3526208-1-peter@korsgaard.com>

Fixes the following security issues:

- CVE-2025-27795: ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks
  image dimension resource limits
  https://nvd.nist.gov/vuln/detail/CVE-2025-27795

- CVE-2025-32460: GraphicsMagick before 8e56520 has a heap-based buffer
  over-read in ReadJXLImage in coders/jxl.c, related to an
  ImportViewPixelArea call.
  https://nvd.nist.gov/vuln/detail/CVE-2025-32460

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
---
 ...pply-image-dimension-resource-limits.patch | 32 ++++++++++
 ...ixel_format-num_channels-needs-to-be.patch | 60 +++++++++++++++++++
 package/graphicsmagick/graphicsmagick.mk      |  6 ++
 3 files changed, 98 insertions(+)
 create mode 100644 package/graphicsmagick/0001-ReadJXLImage-Apply-image-dimension-resource-limits.patch
 create mode 100644 package/graphicsmagick/0002-ReadJXLImage-pixel_format-num_channels-needs-to-be.patch

diff --git a/package/graphicsmagick/0001-ReadJXLImage-Apply-image-dimension-resource-limits.patch b/package/graphicsmagick/0001-ReadJXLImage-Apply-image-dimension-resource-limits.patch
new file mode 100644
index 0000000000..275738a71a
--- /dev/null
+++ b/package/graphicsmagick/0001-ReadJXLImage-Apply-image-dimension-resource-limits.patch
@@ -0,0 +1,32 @@
+# HG changeset patch
+# User Bob Friesenhahn <bfriesen@GraphicsMagick.org>
+# Date 1725886903 18000
+#      Mon Sep 09 08:01:43 2024 -0500
+# Node ID 9bbae7314e3c3b19b830591010ed90bb136b9c42
+# Parent  db3ff8d00c28c38895e1600a28706ce251dac570
+ReadJXLImage(): Apply image dimension resource limits. Addresses oss-fuzz Issue 69728
+
+Upstream: https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/9bbae7314e3c3b19b830591010ed90bb136b9c42
+Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
+[Peter: drop ChangeLog/version changes]
+diff --git a/coders/jxl.c b/coders/jxl.c
+--- a/coders/jxl.c
++++ b/coders/jxl.c
+@@ -571,6 +571,7 @@
+                                       basic_info.alpha_bits, basic_info.num_color_channels,
+                                       basic_info.have_animation == JXL_FALSE ? "False" : "True");
+               }
++
+             if (basic_info.num_extra_channels)
+               {
+                 size_t index;
+@@ -637,6 +638,9 @@
+ 
+             image->orientation=convert_orientation(basic_info.orientation);
+ 
++            if (CheckImagePixelLimits(image, exception) != MagickPass)
++              ThrowJXLReaderException(ResourceLimitError,ImagePixelLimitExceeded,image);
++
+             pixel_format.endianness=JXL_NATIVE_ENDIAN;
+             pixel_format.align=0;
+             if (basic_info.num_color_channels == 1)
diff --git a/package/graphicsmagick/0002-ReadJXLImage-pixel_format-num_channels-needs-to-be.patch b/package/graphicsmagick/0002-ReadJXLImage-pixel_format-num_channels-needs-to-be.patch
new file mode 100644
index 0000000000..d1cc795b4c
--- /dev/null
+++ b/package/graphicsmagick/0002-ReadJXLImage-pixel_format-num_channels-needs-to-be.patch
@@ -0,0 +1,60 @@
+# HG changeset patch
+# User Bob Friesenhahn <bfriesen@GraphicsMagick.org>
+# Date 1743004970 18000
+#      Wed Mar 26 11:02:50 2025 -0500
+# Node ID 8e56520435df50f618a03f2721a39a70a515f1cb
+# Parent  036a1376a2a6dc9504c5148249cbd8feaef72de6
+ReadJXLImage(): pixel_format.num_channels needs to be 2 for grayscale matte.
+
+Upstream: https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/8e56520435df50f618a03f2721a39a70a515f1cb
+Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
+[Peter: drop ChangeLog/version changes]
+
+diff --git a/coders/jxl.c b/coders/jxl.c
+--- a/coders/jxl.c
++++ b/coders/jxl.c
+@@ -658,7 +658,7 @@
+                       ThrowJXLReaderException(ResourceLimitError,MemoryAllocationFailed,image);
+                   }
+                 grayscale=MagickTrue;
+-                pixel_format.num_channels=1;
++                pixel_format.num_channels=image->matte ? 2 : 1;
+                 pixel_format.data_type=(basic_info.bits_per_sample <= 8 ? JXL_TYPE_UINT8 :
+                                         (basic_info.bits_per_sample <= 16 ? JXL_TYPE_UINT16 :
+                                          JXL_TYPE_FLOAT));
+@@ -843,6 +843,24 @@
+             size_t
+               out_len;
+ 
++            if (image->logging)
++              (void) LogMagickEvent(CoderEvent,GetMagickModule(),
++                                    "JxlPixelFormat:\n"
++                                    "    num_channels: %u\n"
++                                    "    data_type: %s\n"
++                                    "    endianness: %s\n"
++                                    "    align: %" MAGICK_SIZE_T_F "u",
++                                    pixel_format.num_channels,
++                                    pixel_format.data_type == JXL_TYPE_FLOAT ? "float" :
++                                    (pixel_format.data_type == JXL_TYPE_UINT8 ? "uint8" :
++                                     (pixel_format.data_type == JXL_TYPE_UINT16 ? "uint16" :
++                                      (pixel_format.data_type == JXL_TYPE_FLOAT16 ? "float16" :
++                                       "unknown"))) ,
++                                    pixel_format.endianness == JXL_NATIVE_ENDIAN ? "native" :
++                                    (pixel_format.endianness == JXL_LITTLE_ENDIAN ? "little" :
++                                     (pixel_format.endianness == JXL_BIG_ENDIAN ? "big" : "unknown")),
++                                    pixel_format.align);
++
+             status=JxlDecoderImageOutBufferSize(jxl_decoder,&pixel_format,&out_len);
+             if (status != JXL_DEC_SUCCESS)
+               {
+@@ -852,6 +870,10 @@
+                 break;
+               }
+ 
++            if (image->logging)
++              (void) LogMagickEvent(CoderEvent,GetMagickModule(),
++                                    "JxlDecoderImageOutBufferSize() returns %" MAGICK_SIZE_T_F "u",
++                                    (MAGICK_SIZE_T) out_len);
+             out_buf=MagickAllocateResourceLimitedArray(unsigned char *,out_len,sizeof(*out_buf));
+             if (out_buf == (unsigned char *) NULL)
+               ThrowJXLReaderException(ResourceLimitError,MemoryAllocationFailed,image);
diff --git a/package/graphicsmagick/graphicsmagick.mk b/package/graphicsmagick/graphicsmagick.mk
index baaa9bcb02..4b9f3bd23c 100644
--- a/package/graphicsmagick/graphicsmagick.mk
+++ b/package/graphicsmagick/graphicsmagick.mk
@@ -11,6 +11,12 @@ GRAPHICSMAGICK_LICENSE = MIT
 GRAPHICSMAGICK_LICENSE_FILES = Copyright.txt
 GRAPHICSMAGICK_CPE_ID_VENDOR = graphicsmagick
 
+# 0001-ReadJXLImage-Apply-image-dimension-resource-limits.patch
+GRAPHICSMAGICK_IGNORE_CVES += CVE-2025-27795
+
+# 0002-ReadJXLImage-pixel_format-num_channels-needs-to-be.patch
+GRAPHICSMAGICK_IGNORE_CVES += CVE-2025-32460
+
 GRAPHICSMAGICK_INSTALL_STAGING = YES
 GRAPHICSMAGICK_CONFIG_SCRIPTS = GraphicsMagick-config GraphicsMagickWand-config
 
-- 
2.39.5

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  reply	other threads:[~2025-04-23 19:06 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-23 19:06 [Buildroot] [PATCH 1/2] package/graphicsmagick: security bump to version 1.3.45 Peter Korsgaard
2025-04-23 19:06 ` Peter Korsgaard [this message]
2025-04-23 19:24 ` Julien Olivain
2025-05-02 11:06 ` Arnout Vandecappelle via buildroot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250423190643.3526208-2-peter@korsgaard.com \
    --to=peter@korsgaard.com \
    --cc=buildroot@buildroot.org \
    --cc=grzegorz@blach.pl \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.