Skip to content

V3: Prevent negative allocation attempt for huge TIFF files - #3004

Merged
JimBobSquarePants merged 1 commit into
release/3.1.xfrom
js/v3-fix-2959
Oct 24, 2025
Merged

V3: Prevent negative allocation attempt for huge TIFF files#3004
JimBobSquarePants merged 1 commit into
release/3.1.xfrom
js/v3-fix-2959

Conversation

@JimBobSquarePants

@JimBobSquarePantsJimBobSquarePants commented Oct 24, 2025

Copy link
Copy Markdown
Member

Prerequisites

  • I have written a descriptive pull-request title
  • I have verified that there are no overlapping pull-requests open
  • I have verified that I am following the existing coding patterns and practice as demonstrated in the repository. These follow strict Stylecop rules 👮.
  • I have provided test coverage for my change (where applicable)

Description

Fixes#2959

Backport of #3003 for v3

@JimBobSquarePants
JimBobSquarePants merged commit 6b7448e into release/3.1.xOct 24, 2025
22 checks passed
@JimBobSquarePants
JimBobSquarePants deleted the js/v3-fix-2959 branch October 24, 2025 07:22
IhateTrains pushed a commit to ParadoxGameConverters/ImperatorToCK3 that referenced this pull request Oct 30, 2025
Updated [SixLabors.ImageSharp](https://github.com/SixLabors/ImageSharp)
from 3.1.11 to 3.1.12.
<details>
<summary>Release notes</summary>
_Sourced from [SixLabors.ImageSharp's
releases](https://github.com/SixLabors/ImageSharp/releases)._
## 3.1.12
## What's Changed
* v3 : Add Full Metadata Parsing for WEBP Animations by
@​JimBobSquarePants in SixLabors/ImageSharp#3002
* V3: Prevent negative allocation attempt for huge TIFF files by
@​JimBobSquarePants in SixLabors/ImageSharp#3004
* Backport v3 : Tiff decoder: Fix issue 2679 by @​JimBobSquarePants in
SixLabors/ImageSharp#3007
**Full Changelog**:
SixLabors/ImageSharp@v3.1.11...v3.1.12
Commits viewable in [compare
view](SixLabors/ImageSharp@v3.1.11...v3.1.12).
</details>
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=SixLabors.ImageSharp&package-manager=nuget&previous-version=3.1.11&new-version=3.1.12)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@JimBobSquarePants