From 6caeaa3a14c0f89ec81a139876e5fd68d535be60 Mon Sep 17 00:00:00 2001 From: Tristan Date: Thu, 26 Mar 2026 14:07:53 -0400 Subject: [PATCH] bmp: add pixel count limit for large dimensions The BMP decoder does not validate the relationship between width and height values read from the file header. Very large dimensions can cause image.New* to panic instead of returning an error. Add a pixel count check (1<<30, approximately 1 billion pixels) to convert this panic into a proper error return. This is consistent with the TIFF decoder's maxChunkSize approach for bounding allocations from untrusted input. --- bmp/reader.go | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/bmp/reader.go b/bmp/reader.go index fa9083d4..35812091 100644 --- a/bmp/reader.go +++ b/bmp/reader.go @@ -183,6 +183,14 @@ func decodeConfig(r io.Reader) (config image.Config, bitsPerPixel int, topDown b if width < 0 || height < 0 { return image.Config{}, 0, false, false, ErrUnsupported } + // Reject dimensions where the pixel buffer would be unreasonably large. + // At 4 bytes per pixel (NRGBA), this limit caps the allocation at ~4 GiB, + // which prevents image.New* from panicking on oversized inputs. This is + // consistent with the TIFF decoder's use of maxChunkSize for similar + // bounds checking. + if int64(width)*int64(height) > 1<<30 { + return image.Config{}, 0, false, false, ErrUnsupported + } // We only support 1 plane and 8, 24 or 32 bits per pixel and no // compression. planes, bpp, compression := readUint16(b[26:28]), readUint16(b[28:30]), readUint32(b[30:34])