Skip to content

fix: bound JBIG2 arithmetic and symbol decoding - #1159

Merged
andiwand merged 2 commits into
mainfrom
review/141-jbig2-bounds
Oct 6, 2026
Merged

andiwand merged 2 commits into
mainfrom
review/141-jbig2-bounds

Conversation

@andiwand

@andiwand andiwand commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

🤖 Generated with Claude Code

Malformed JBIG2 data could overflow arithmetic integer decoding and region placement, allocate excessive symbol tables, or keep symbol loops running without progress. Intermediate regions were also painted onto the page even though their use is unsupported.

Check integer and symbol bounds, use wider placement arithmetic, clip before composition, cap cumulative symbol pixels, and reject inconsistent exports and nonprogressing height classes. Unsupported intermediate regions now fail the image. Limits are documented in the PDF module instructions.

Validation: the parent fails both focused regression cases; UBSan independently reproduces the arithmetic and placement overflows. All 55 JBIG2/image/filter tests and 50 PDF corpus HTML-generation tests pass. ASan/UBSan pass placement checks and two million deterministic arithmetic decoding trials. LLVM 22 clang-tidy and object builds for NDK 28.1, emsdk 3.1.73 and iOS 15 pass.

@andiwand
andiwand force-pushed the review/140-pdf-object-tokens branch from adf0a7b to 566cc05 Compare October 6, 2026 18:34
Base automatically changed from review/140-pdf-object-tokens to main October 6, 2026 18:36
andiwand and others added 2 commits October 6, 2026 20:36
decode_symbol_dictionary wrote the stream's remaining symbol pixels
through a reference. It now takes the budget by value and returns the
pixels its new symbols use next to the exported symbols, and the caller
subtracts them.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MxyTMutqSUJRGfxA8CyzMc
@andiwand
andiwand force-pushed the review/141-jbig2-bounds branch from cb86575 to b03c16a Compare October 6, 2026 18:41
@andiwand
andiwand merged commit 816dac9 into main Oct 6, 2026
23 of 25 checks passed
@andiwand
andiwand deleted the review/141-jbig2-bounds branch October 6, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant