Skip to content

bound dilate and erode width to avoid mask-size overflow - #4548

Merged
lovell merged 2 commits into
lovell:mainfrom
metsw24-max:dilate-erode-bound-width
Jun 17, 2026
Merged

lovell merged 2 commits into
lovell:mainfrom
metsw24-max:dilate-erode-bound-width

Conversation

@metsw24-max

Copy link
Copy Markdown
Contributor

Unbounded dilate/erode width overflows the mask size

dilate() and erode() accept any positive integer, unlike the sibling median() which bounds its window to 1 to 1000, so an oversized width reaches the native Dilate/Erode where the structuring element is sized as 2 * width + 1 and passed to new_matrix; read through AttrAsUint32 into an int, a width of 2^30 wraps that signed size negative and 2^32 narrows it to zero, silently dropping the operation. Bounded the width to match median so the value can no longer reach that calculation.

@lovell

lovell commented Jun 17, 2026

Copy link
Copy Markdown
Owner

Thanks for the PR to fix this. Is there a reason for the 1000 limit? I think it might need to be a bit higher than this, perhaps 65536 (1 << 16)?

@lovell lovell added this to the v0.35.2 milestone Jun 17, 2026
@metsw24-max

Copy link
Copy Markdown
Contributor Author

No strong reason for 1000, I just matched the bound median() uses for its window. 65536 is fine here. The only value that needs guarding is the 2 * width + 1 mask size, and at 65536 that comes to 131073, still well within int. Pushed a change bounding both to 1..65536.

@lovell
lovell merged commit ab52866 into lovell:main Jun 17, 2026
32 checks passed
@lovell

lovell commented Jun 17, 2026

Copy link
Copy Markdown
Owner

Thank you

suparious pushed a commit to SolidRusT/solidrust-ai-docs.github.io that referenced this pull request Oct 3, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [sharp](https://sharp.pixelplumbing.com) ([source](https://github.com/lovell/sharp), [changelog](https://github.com/lovell/sharp/blob/main/docs/src/content/docs/changelog.md)) | dependencies | minor | [`^0.33.5` → `^0.35.5`](https://renovatebot.com/diffs/npm/sharp/0.33.5/0.35.5) |

---

### Release Notes

<details>
<summary>lovell/sharp (sharp)</summary>

### [`v0.35.5`](https://github.com/lovell/sharp/releases/tag/v0.35.5)

[Compare Source](lovell/sharp@v0.35.4...v0.35.5)

<https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4>

- Add upper bounds check on length of `linear` and GIF `delay` arrays.

- Improve error handing when WebAssembly fallback also fails.
  [#&#8203;4593](lovell/sharp#4593)
  [@&#8203;lazerg](https://github.com/lazerg)

- TypeScript: Allow multi-frame options for JXL output.
  [#&#8203;4602](lovell/sharp#4602)
  [@&#8203;ramin-010](https://github.com/ramin-010)

- TypeScript: Remove non-existent named export.
  [#&#8203;4604](lovell/sharp#4604)

- Increase accepted dimensions when extending an image.
  [#&#8203;4605](lovell/sharp#4605)

- Improve gain map support for `extract` and `rotate` operations.
  [#&#8203;4606](lovell/sharp#4606)

- Tests: Ensure composite tests pass on big endian platforms.
  [#&#8203;4609](lovell/sharp#4609)

### [`v0.35.4`](https://github.com/lovell/sharp/releases/tag/v0.35.4)

[Compare Source](lovell/sharp@v0.35.3...v0.35.4)

<https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3>

- Bound resize dimensions to coordinate limit.

- Bound composite left and top to coordinate limit.
  [#&#8203;4564](lovell/sharp#4564)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Round palette bit depth up for png and gif colours.
  [#&#8203;4569](lovell/sharp#4569)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Ensure tiff.subifd input option is used.
  [#&#8203;4572](lovell/sharp#4572)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Ensure `info.pages` is correct when limiting input page range.
  [#&#8203;4578](lovell/sharp#4578)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Improve support for input Streams finishing before output is requested.
  [#&#8203;4584](lovell/sharp#4584)
  [@&#8203;Jaybhade](https://github.com/Jaybhade)

### [`v0.35.3`](https://github.com/lovell/sharp/releases/tag/v0.35.3)

[Compare Source](lovell/sharp@v0.35.2...v0.35.3)

- Tighten verification of `text` dimensions, TIFF tile dimensions and `extend` values.

- Improve code bundler support by resolving path to libvips binary.

- Increase default concurrency when use of `MALLOC_ARENA_MAX` is detected.

- Emit warning about binaries provided by Electron for use on Linux.

- Add `hasAlpha` property to output `info`.
  [#&#8203;4500](lovell/sharp#4500)

- TypeScript: Return more precise `Buffer<ArrayBuffer>` from `toBuffer`.
  [#&#8203;4520](lovell/sharp#4520)
  [@&#8203;Andarist](https://github.com/Andarist)

- Bound `clahe` width and height to avoid signed overflow.
  [#&#8203;4551](lovell/sharp#4551)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Bound `trim` margin to avoid signed overflow.
  [#&#8203;4552](lovell/sharp#4552)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Reject infinite values when validating numbers.
  [#&#8203;4553](lovell/sharp#4553)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Bound extract region to libvips coordinate limit.
  [#&#8203;4555](lovell/sharp#4555)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Verify background colour values are numbers.
  [#&#8203;4556](lovell/sharp#4556)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Bound create and raw input dimensions to coordinate limit.
  [#&#8203;4558](lovell/sharp#4558)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Tighten recomb and affine matrix verification.
  [#&#8203;4560](lovell/sharp#4560)
  [@&#8203;chatman-media](https://github.com/chatman-media)

- Verify cache memory limit to avoid overflow.
  [#&#8203;4561](lovell/sharp#4561)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

### [`v0.35.2`](https://github.com/lovell/sharp/releases/tag/v0.35.2)

[Compare Source](lovell/sharp@v0.35.1...v0.35.2)

- TypeScript: Add `mediaType` to metadata response.
  [#&#8203;4492](lovell/sharp#4492)

- Improve WebAssembly fallback detection.
  [#&#8203;4513](lovell/sharp#4513)

- Improve code bundler support with stub binaries.
  [#&#8203;4543](lovell/sharp#4543)

- Verify GIF `effort` option is an integer.
  [#&#8203;4544](lovell/sharp#4544)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Verify `recomb` matrix entries are numbers.
  [#&#8203;4545](lovell/sharp#4545)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- TypeScript: Replace namespace with named exports for ESM.
  [#&#8203;4546](lovell/sharp#4546)

- Bound dilate and erode width to avoid mask-size overflow.
  [#&#8203;4548](lovell/sharp#4548)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Verify `convolve` kernel values are numbers.
  [#&#8203;4549](lovell/sharp#4549)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

### [`v0.35.1`](https://github.com/lovell/sharp/releases/tag/v0.35.1)

[Compare Source](lovell/sharp@v0.35.0...v0.35.1)

- TypeScript: Ensure type definitions are published for both ESM and CJS.
  [#&#8203;4537](lovell/sharp#4537)

- WebAssembly: Ensure wrapper file is published.
  [#&#8203;4538](lovell/sharp#4538)

### [`v0.35.0`](https://github.com/lovell/sharp/releases/tag/v0.35.0)

[Compare Source](lovell/sharp@v0.34.5...v0.35.0)

- Breaking: Drop support for Node.js 18, now requires Node.js >= 20.9.0.

- Breaking: Remove `install` script from `package.json` file.
  Compiling from source is now opt-in via the `build` script.

- Breaking: Lossy AVIF output is now tuned using SSIMULACRA2-based `iq` quality metrics.

- Breaking: Add `limitInputChannels` with a default value of 5.

- Breaking: Remove deprecated `failOnError` constructor property.

- Breaking: Remove deprecated `paletteBitDepth` from `metadata` response.

- Breaking: Remove deprecated properties from `sharpen` operation.

- Breaking: Rename `format.jp2k` as `format.jp2` for API consistency.

- Upgrade to libvips v8.18.3 for upstream bug fixes.

- Remove experimental status from WebAssembly binaries.

- Add prebuilt binaries for FreeBSD (WebAssembly).

- Deprecate Windows 32-bit (win32-ia32) prebuilt binaries.

- Ensure TIFF output `bitdepth` option is limited to 1, 2 or 4.

- Add AVIF/HEIF `tune` option for control over quality metrics.
  [#&#8203;4227](lovell/sharp#4227)

- Add `keepGainMap` and `withGainMap` to process HDR JPEG images with embedded gain maps.
  [#&#8203;4314](lovell/sharp#4314)

- Add `toUint8Array` for output image as a `TypedArray` backed by a transferable `ArrayBuffer`.
  [#&#8203;4355](lovell/sharp#4355)

- Require prebuilt binaries using static paths to aid code bundling.
  [#&#8203;4380](lovell/sharp#4380)

- TypeScript: Ensure `FormatEnum` keys match reality.
  [#&#8203;4475](lovell/sharp#4475)

- Add `margin` option to `trim` operation.
  [#&#8203;4480](lovell/sharp#4480)
  [@&#8203;eddienubes](https://github.com/eddienubes)

- Ensure HEIF primary item is used as default page/frame.
  [#&#8203;4487](lovell/sharp#4487)

- Add image Media Type (MIME Type) to metadata response.
  [#&#8203;4492](lovell/sharp#4492)

- Add `withDensity` to set output density in EXIF metadata.
  [#&#8203;4496](lovell/sharp#4496)

- Improve `pkg-config` path discovery.
  [#&#8203;4504](lovell/sharp#4504)

- Add WebP `exact` option for control over transparent pixel colour values.

- Add support for ECMAScript Modules (ESM).
  [#&#8203;4509](lovell/sharp#4509)
  [@&#8203;florian-lefebvre](https://github.com/florian-lefebvre)

### [`v0.34.5`](https://github.com/lovell/sharp/releases/tag/v0.34.5)

[Compare Source](lovell/sharp@v0.34.4...v0.34.5)

- Upgrade to libvips v8.17.3 for upstream bug fixes.

- Add experimental support for prebuilt Linux RISC-V 64-bit binaries.

- Support building from source with npm v12+, deprecate `--build-from-source` flag.
  [#&#8203;4458](lovell/sharp#4458)

- Add support for BigTIFF output.
  [#&#8203;4459](lovell/sharp#4459)
  [@&#8203;throwbi](https://github.com/throwbi)

- Improve error messaging when only warnings issued.
  [#&#8203;4465](lovell/sharp#4465)

- Simplify ICC processing when retaining input profiles.
  [#&#8203;4468](lovell/sharp#4468)

### [`v0.34.4`](https://github.com/lovell/sharp/releases/tag/v0.34.4)

[Compare Source](lovell/sharp@v0.34.3...v0.34.4)

- Upgrade to libvips v8.17.2 for upstream bug fixes.

- Ensure TIFF `subifd` and OpenSlide `level` input options are respected (regression in 0.34.3).

- Ensure `autoOrient` occurs before non-90 angle rotation.
  [#&#8203;4425](lovell/sharp#4425)

- Ensure `autoOrient` removes existing metadata after shrink-on-load.
  [#&#8203;4431](lovell/sharp#4431)

- TypeScript: Ensure `KernelEnum` includes `linear`.
  [#&#8203;4441](lovell/sharp#4441)
  [@&#8203;BayanBennett](https://github.com/BayanBennett)

- Ensure `unlimited` flag is passed upstream when reading TIFF images.
  [#&#8203;4446](lovell/sharp#4446)

- Support Electron memory cage when reading XMP metadata (regression in 0.34.3).
  [#&#8203;4451](lovell/sharp#4451)

- Add sharp-libvips rpath for yarn v5 support.
  [#&#8203;4452](lovell/sharp#4452)
  [@&#8203;arcanis](https://github.com/arcanis)

### [`v0.34.3`](lovell/sharp@v0.34.2...v0.34.3)

[Compare Source](lovell/sharp@v0.34.2...v0.34.3)

### [`v0.34.2`](lovell/sharp@v0.34.1...v0.34.2)

[Compare Source](lovell/sharp@v0.34.1...v0.34.2)

### [`v0.34.1`](lovell/sharp@v0.34.0...v0.34.1)

[Compare Source](lovell/sharp@v0.34.0...v0.34.1)

### [`v0.34.0`](lovell/sharp@v0.33.5...v0.34.0)

[Compare Source](lovell/sharp@v0.33.5...v0.34.0)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [x] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMzIuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjEzMi4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

---------

Co-authored-by: Renovate Bot <[email protected]>
Reviewed-on: https://gitea.hq.solidrust.net:30008/solidrust/solidrust-ai-docs.github.io/pulls/9
Co-authored-by: renovate-bot <[email protected]>
Co-committed-by: renovate-bot <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants