Skip to content

AccessViolationException when loading TIFF image #2123

Description

@botinko

Prerequisites

  • I have written a descriptive issue title
  • I have verified that I am running the latest version of ImageSharp
  • I have verified if the problem exist in both DEBUG and RELEASE mode
  • I have searched open and closed issues to ensure it has not already been reported

ImageSharp version

2.1.1

Other ImageSharp packages and versions

2.1.1

Environment (Operating system, version and so on)

Windows 10 21H2, Linux

.NET Framework version

.NET 5

Description

    using var fileStream = File.Open("error.tiff", FileMode.Open);
    Image.Load(fileStream);
Fatal error. System.AccessViolationException: Attempted to read or write protected memory. This is often an indication that other memory is corrupt.
   at SixLabors.ImageSharp.Formats.Tiff.PhotometricInterpretation.YCbCrTiffColor`1[[SixLabors.ImageSharp.PixelFormats.Rgba32, SixLabors.ImageSharp, Version=2.0.0.0, Culture=neutral,
 PublicKeyToken=d998eea7b14cab13]].Decode(System.ReadOnlySpan`1<Byte>, SixLabors.ImageSharp.Memory.Buffer2D`1<SixLabors.ImageSharp.PixelFormats.Rgba32>, Int32, Int32, Int32, Int32)
   at SixLabors.ImageSharp.Formats.Tiff.TiffDecoderCore.DecodeStripsChunky[[SixLabors.ImageSharp.PixelFormats.Rgba32, SixLabors.ImageSharp, Version=2.0.0.0, Culture=neutral, PublicK
eyToken=d998eea7b14cab13]](SixLabors.ImageSharp.ImageFrame`1<SixLabors.ImageSharp.PixelFormats.Rgba32>, Int32, System.Span`1<UInt64>, System.Span`1<UInt64>, System.Threading.Cancell
ationToken)
   at SixLabors.ImageSharp.Formats.Tiff.TiffDecoderCore.DecodeFrame[[SixLabors.ImageSharp.PixelFormats.Rgba32, SixLabors.ImageSharp, Version=2.0.0.0, Culture=neutral, PublicKeyToken
=d998eea7b14cab13]](SixLabors.ImageSharp.Metadata.Profiles.Exif.ExifProfile, System.Threading.CancellationToken)
   at SixLabors.ImageSharp.Formats.Tiff.TiffDecoderCore.Decode[[SixLabors.ImageSharp.PixelFormats.Rgba32, SixLabors.ImageSharp, Version=2.0.0.0, Culture=neutral, PublicKeyToken=d998
eea7b14cab13]](SixLabors.ImageSharp.IO.BufferedReadStream, System.Threading.CancellationToken)
   at SixLabors.ImageSharp.Formats.ImageDecoderUtilities.Decode[[SixLabors.ImageSharp.PixelFormats.Rgba32, SixLabors.ImageSharp, Version=2.0.0.0, Culture=neutral, PublicKeyToken=d99
8eea7b14cab13]](SixLabors.ImageSharp.Formats.IImageDecoderInternals, SixLabors.ImageSharp.Configuration, System.IO.Stream, System.Func`3<SixLabors.ImageSharp.Memory.InvalidMemoryOpe
rationException,SixLabors.ImageSharp.Size,SixLabors.ImageSharp.InvalidImageContentException>, System.Threading.CancellationToken)
   at SixLabors.ImageSharp.Formats.ImageDecoderUtilities.Decode[[SixLabors.ImageSharp.PixelFormats.Rgba32, SixLabors.ImageSharp, Version=2.0.0.0, Culture=neutral, PublicKeyToken=d99
8eea7b14cab13]](SixLabors.ImageSharp.Formats.IImageDecoderInternals, SixLabors.ImageSharp.Configuration, System.IO.Stream, System.Threading.CancellationToken)
   at SixLabors.ImageSharp.Formats.Tiff.TiffDecoder.Decode[[SixLabors.ImageSharp.PixelFormats.Rgba32, SixLabors.ImageSharp, Version=2.0.0.0, Culture=neutral, PublicKeyToken=d998eea7
b14cab13]](SixLabors.ImageSharp.Configuration, System.IO.Stream, System.Threading.CancellationToken)
   at SixLabors.ImageSharp.Formats.Tiff.TiffDecoder.Decode(SixLabors.ImageSharp.Configuration, System.IO.Stream, System.Threading.CancellationToken)
   at SixLabors.ImageSharp.Image.Decode(System.IO.Stream, SixLabors.ImageSharp.Configuration, System.Threading.CancellationToken)
   at SixLabors.ImageSharp.Image+<>c__DisplayClass134_0.<Load>b__0(System.IO.Stream)
   at SixLabors.ImageSharp.Image.WithSeekableStream[[System.ValueTuple`2[[System.__Canon, System.Private.CoreLib, Version=5.0.0.0, Culture=neutral, PublicKeyToken=7cec85d7bea7798e],
[System.__Canon, System.Private.CoreLib, Version=5.0.0.0, Culture=neutral, PublicKeyToken=7cec85d7bea7798e]], System.Private.CoreLib, Version=5.0.0.0, Culture=neutral, PublicKeyToke
n=7cec85d7bea7798e]](SixLabors.ImageSharp.Configuration, System.IO.Stream, System.Func`2<System.IO.Stream,System.ValueTuple`2<System.__Canon,System.__Canon>>)
   at SixLabors.ImageSharp.Image.Load(SixLabors.ImageSharp.Configuration, System.IO.Stream, SixLabors.ImageSharp.Formats.IImageFormat ByRef)
   at SixLabors.ImageSharp.Image.Load(SixLabors.ImageSharp.Configuration, System.IO.Stream)
   at SixLabors.ImageSharp.Image.Load(System.IO.Stream)
   at ConsoleApp22.Program.Main(System.String[])

Steps to Reproduce

Just load a problematic error.tiff from attachment.

Images

error.zip

Activity

  1. changed the title [-]System.ExecutionEngineException when loading TIFF image[/-] [+]AccessViolationExceptionwhen loading TIFF image[/+] on May 20, 2022
  2. changed the title [-]AccessViolationExceptionwhen loading TIFF image[/-] [+]AccessViolationException when loading TIFF image[/+] on May 20, 2022
  3. brianpopow commented on May 20, 2022

    @brianpopow
    Collaborator

    @botinko is it ok, if we use the provided image in unit tests?

  4. self-assigned this
    on May 20, 2022
  5. botinko commented on May 20, 2022

    @botinko
    Author

    @botinko is it ok, if we use the provided image in unit tests?

    Sorry, but this is an image from our client and it didn't give permission for that.

  6. brianpopow commented on May 20, 2022

    @brianpopow
    Collaborator

    ok no problem, I will try to create a similar one with the same properties.

  7. brianpopow commented on May 20, 2022

    @brianpopow
    Collaborator

    I think I found the reason for the Exception: See branch FixIssue2123

    While the image decodes now without errors, the colors seem to be wrong. The image is all pink. This indicates the wrong colorspace is determined. The image uses Jpeg compression and the Photometric Interpretation is YCbCr. It seems this should be decoded as RGB instead of YCbCr. Not sure howto deal with that as the Photometric Interpretation clearly states it should be YCbCr.

    tiffinfo output:

    TIFFFetchNormalTag: Warning, ASCII value for tag "Software" does not end in null byte.
    TIFF Directory at offset 0x8 (8)
      Subfile Type: multi-page document (2 = 0x2)
      Image Width: 2550 Image Length: 3300
      Resolution: 300, 300 pixels/inch
      Bits/Sample: 8
      Compression Scheme: JPEG
      Photometric Interpretation: YCbCr
      FillOrder: msb-to-lsb
      YCbCr Subsampling: 2, 2
      YCbCr Positioning: centered
      Orientation: row 0 top, col 0 lhs
      Samples/Pixel: 3
      Rows/Strip: 3300
      Planar Configuration: single image plane
      Page Number: 0-0
      Software: KM_C308
      DateTime: 2022:05:19 15:56:57
    
  8. br3aker commented on May 20, 2022

    @br3aker
    Contributor

    @brianpopow it's rather strange that RGB would use chroma subsampling. Looks like the image itself is corrupted.

  9. JimBobSquarePants commented on May 20, 2022

    @JimBobSquarePants
    Member

    Are we absolutely, positively sure we're detecting the colorspace properly?

    Given that I can open the file just fine using Paint.NET it suggests we're detecting something incorrectly.

    EDIT
    tiffinfo is part of the libtiff toolset isn't it? So we're probably detecting the colorspace correctly.

    For debugging ease I would suggest opening the image using LibTiff.NET and if it's successful we can step through and see what is going on.

  10. brianpopow commented on May 20, 2022

    @brianpopow
    Collaborator

    tiffinfo is from libtiff, yes. The component id's of the jpeg data are 1, 2 and 3, which according to jpeg_metadata, also indicates it should be YCbCr instead of RGB. So I also think there is something wrong with the image, but imagemagick can convert this image also without problems. Im not sure how we can determine that this should be RGB rather then YCBCr.

  11. br3aker commented on May 20, 2022

    @br3aker
    Contributor

    The component id's of the jpeg data are 1, 2 and 3, which according to jpeg_metadata, also indicates it should be YCbCr instead of RGB.

    It's not that simple, component id is a 'hint' that this may be a YCbCr encoded image. Adobe APP14 marker decides what exact ebcoding was used, i.e.

    if(componentCount == 3)
    {
        if (app14Marker == null)
        {
            // fallback to default 3 component encoding - YCbCr
        }
        else if(app14Marker.IsYCbCr) { /* Explicit YCbCr */ }
        else { /* RGB */ }
    }
    
  12. botinko commented on May 20, 2022

    @botinko
    Author

    Thank you, guys! For us, it was enough that there was no AccessViolationException, which causes the application to crash. I would like to get the Exception, which I can catch in case if image have wrong header.

  13. brianpopow commented on May 20, 2022

    @brianpopow
    Collaborator

    Ok, I think I do understand now what is going wrong here with the colors:

    The image has PhotometricInterpretation set to YCbCr and is JpegCompressed. What is happening now is that decompressor (jpeg decoder) will decompress the data and converts it from YCbCr to RGB, then the Tiff Decoder again converts to YCbCr, because the PhotometricInterpretation is YCbCr (which is one time too much). If the image is compressed with JPEG, the jpeg decoder should take care of the conversion and not the TiffDecoder.

  14. brianpopow commented on May 26, 2022

    @brianpopow
    Collaborator

    With #2124 merged, this issue is fixed. There is a new nuget version 2.1.2 of ImageSharp with this fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions