Executive brief
libsixel is a library used to convert images into the SIXEL format for display in terminal emulators. A security flaw in its image cropping feature allows a specially crafted command to cause the application to crash or potentially leak sensitive information from memory. This occurs when the software processes extremely large coordinate values without proper safety checks.
Technical details
An integer overflow exists in the `sixel_encoder_do_clip()` function of libsixel. When the `--crop` option is used with a coordinate value near INT_MAX (e.g., 2,147,483,647), the bounds check `clip_w + clip_x > src_width` overflows to a negative value, bypassing the safety guard. This unclamped coordinate is eventually passed to `memmove()`, which attempts to read from a source pointer calculated far beyond the allocated image buffer. This results in an out-of-bounds heap read, causing a reliable application crash and potential information disclosure. The vulnerability is exploitable if a user is convinced to run the `img2sixel` utility with a malicious crop argument against a valid image.
Affected products
- saitoha libsixel <= 1.8.7
Timeline
- 2026-04-14: disclosed
- 2026-04-14: patched: Fixed in version 1.8.7-r1
- 2026-04-14: advisory