[php-src] PHP-8.5: Bound the HEIF meta box allocation by the file size

Ilia Alshanetsky <[email protected]>
Newsgroups gmane.comp.php.cvs.general
Message-ID <[email protected]>
Author: Ilia Alshanetsky (iliaal)
Date: 2026-08-11T07:19:28-04:00

Commit: https://github.com/php/php-src/commit/82ac0da470086295313e977c26243b2e726afd7b
Raw diff: https://github.com/php/php-src/commit/82ac0da470086295313e977c26243b2e726afd7b.diff

Bound the HEIF meta box allocation by the file size

exif_scan_HEIF_header() allocated box.size - box_header_size with only a
lower bound, so a 37-byte file could claim a 128MB meta box and force the
allocation before any read is attempted. The second allocation in the
same block is already bounded by pos.size < ImageInfo->FileSize; apply
the same bound to the first.

Closes GH-23201

Changed paths:
  A  ext/exif/tests/heic_meta_box_alloc.phpt
  M  NEWS
  M  ext/exif/exif.c


Diff:

diff --git a/NEWS b/NEWS
index 299678d0a008..ffc76ae4a64b 100644
--- a/NEWS
+++ b/NEWS
@@ -20,6 +20,10 @@ PHP                                                                        NEWS
   . Fixed bug GH-23120 (Stack overflow when comparing deeply nested DOM nodes
     with DOMNode::isEqualNode()). (Weilin Du)
 
+- Exif:
+  . Fixed exif_read_data() allocating a HEIF meta box larger than the file
+    it came from. (iliaal)
+
 - Intl:
   . Fixed IntlListFormatter::__construct() leaving stale global error state
     after successful calls. (Weilin Du)
diff --git a/ext/exif/exif.c b/ext/exif/exif.c
index b30644f155cf..a2eb8259ac71 100644
--- a/ext/exif/exif.c
+++ b/ext/exif/exif.c
@@ -4415,7 +4415,7 @@ static bool exif_scan_HEIF_header(image_info_type *ImageInfo, unsigned char *buf
 		}
 		if (box.type == FOURCC("meta")) {
 			limit = box.size - box_header_size;
-			if (limit < 36) {
+			if (limit < 36 || limit > ImageInfo->FileSize) {
 				break;
 			}
 			data = (unsigned char *)emalloc(limit);
diff --git a/ext/exif/tests/heic_meta_box_alloc.phpt b/ext/exif/tests/heic_meta_box_alloc.phpt
new file mode 100644
index 000000000000..ddc9e415b830
--- /dev/null
+++ b/ext/exif/tests/heic_meta_box_alloc.phpt
@@ -0,0 +1,23 @@
+--TEST--
+HEIC meta box size must be bounded by the file size
+--EXTENSIONS--
+exif
+--INI--
+memory_limit=32M
+--FILE--
+<?php
+// ftyp box (size 20) followed by a meta box whose size field claims 128MB,
+// in a file that is only 37 bytes. Without an upper bound the meta box
+// allocation exhausts memory_limit before any read is attempted.
+$ftyp = pack("N", 20) . "ftypheic" . str_repeat("\x00", 8);
+$meta = pack("N", 0x08000000) . "meta" . str_repeat("\x00", 8);
+file_put_contents(__DIR__."/heic_meta_box_alloc.heic", $ftyp . $meta . "\x00");
+var_dump(exif_read_data(__DIR__."/heic_meta_box_alloc.heic"));
+?>
+--CLEAN--
+<?php
+@unlink(__DIR__."/heic_meta_box_alloc.heic");
+?>
+--EXPECTF--
+Warning: exif_read_data(heic_meta_box_alloc.heic): Invalid HEIF file in %s on line %d
+bool(false)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.