about summary refs log tree commit diff
path: root/lib/redis
diff options
context:
space:
mode:
authorPierre Bourdon <delroth@gmail.com>2022-11-11 07:45:16 +0100
committerGitHub <noreply@github.com>2022-11-11 07:45:16 +0100
commit36bc90e8aaf89b5cf64636b404611ff1809ad6f0 (patch)
tree470fd2cf5e645cee01ad821a791d8f1a066feb6c /lib/redis
parent73fecc3358bc22a1a83772c62593161267369a1e (diff)
blurhash_transcoder: prevent out-of-bound reads with <8bpp images (#20388)
The Blurhash library used by Mastodon requires an input encoded as 24
bits raw RGB data. The conversion to raw RGB using Imagemagick did not
previously specify the desired bit depth. In some situations, this leads
Imagemagick to output in a pixel format using less bpp than expected.
This then manifested as segfaults of the Sidekiq process due to
out-of-bounds read, or potentially a (highly noisy) memory infoleak.

Fixes #19235.
Diffstat (limited to 'lib/redis')
0 files changed, 0 insertions, 0 deletions