From 955ed3f3e4fc2a597048f0efe102b0c43763b99a Mon Sep 17 00:00:00 2001 From: metsw24-max Date: Wed, 17 Jun 2026 16:41:45 +0530 Subject: [PATCH 1/2] bound dilate and erode width to avoid mask-size overflow --- lib/operation.mjs | 8 ++++---- test/unit/dilate.js | 7 +++++++ test/unit/erode.js | 7 +++++++ 3 files changed, 18 insertions(+), 4 deletions(-) diff --git a/lib/operation.mjs b/lib/operation.mjs index 10e2aa439..52a33601b 100644 --- a/lib/operation.mjs +++ b/lib/operation.mjs @@ -424,10 +424,10 @@ function blur (options) { function dilate (width) { if (!is.defined(width)) { this.options.dilateWidth = 1; - } else if (is.integer(width) && width > 0) { + } else if (is.integer(width) && is.inRange(width, 1, 1000)) { this.options.dilateWidth = width; } else { - throw is.invalidParameterError('dilate', 'positive integer', dilate); + throw is.invalidParameterError('width', 'integer between 1 and 1000', width); } return this; } @@ -447,10 +447,10 @@ function dilate (width) { function erode (width) { if (!is.defined(width)) { this.options.erodeWidth = 1; - } else if (is.integer(width) && width > 0) { + } else if (is.integer(width) && is.inRange(width, 1, 1000)) { this.options.erodeWidth = width; } else { - throw is.invalidParameterError('erode', 'positive integer', erode); + throw is.invalidParameterError('width', 'integer between 1 and 1000', width); } return this; } diff --git a/test/unit/dilate.js b/test/unit/dilate.js index bc6f49bf0..9322b99bc 100644 --- a/test/unit/dilate.js +++ b/test/unit/dilate.js @@ -32,4 +32,11 @@ suite('Dilate', () => { sharp(fixtures.inputJpg).dilate(-1); }); }); + + test('oversized dilation width is rejected', (t) => { + t.plan(1); + t.assert.throws(() => { + sharp(fixtures.inputJpg).dilate(2147483648); + }); + }); }); diff --git a/test/unit/erode.js b/test/unit/erode.js index f6dbb81f2..7f61fdb8d 100644 --- a/test/unit/erode.js +++ b/test/unit/erode.js @@ -32,4 +32,11 @@ suite('Erode', () => { sharp(fixtures.inputJpg).erode(-1); }); }); + + test('oversized erosion width is rejected', (t) => { + t.plan(1); + t.assert.throws(() => { + sharp(fixtures.inputJpg).erode(2147483648); + }); + }); }); From 7bae61c1bde09688b23d9e28d5fcc1994f181ea6 Mon Sep 17 00:00:00 2001 From: metsw24-max Date: Wed, 17 Jun 2026 18:16:35 +0530 Subject: [PATCH 2/2] raise dilate and erode width bound to 65536 --- lib/operation.mjs | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/lib/operation.mjs b/lib/operation.mjs index 52a33601b..8ae233527 100644 --- a/lib/operation.mjs +++ b/lib/operation.mjs @@ -424,10 +424,10 @@ function blur (options) { function dilate (width) { if (!is.defined(width)) { this.options.dilateWidth = 1; - } else if (is.integer(width) && is.inRange(width, 1, 1000)) { + } else if (is.integer(width) && is.inRange(width, 1, 65536)) { this.options.dilateWidth = width; } else { - throw is.invalidParameterError('width', 'integer between 1 and 1000', width); + throw is.invalidParameterError('width', 'integer between 1 and 65536', width); } return this; } @@ -447,10 +447,10 @@ function dilate (width) { function erode (width) { if (!is.defined(width)) { this.options.erodeWidth = 1; - } else if (is.integer(width) && is.inRange(width, 1, 1000)) { + } else if (is.integer(width) && is.inRange(width, 1, 65536)) { this.options.erodeWidth = width; } else { - throw is.invalidParameterError('width', 'integer between 1 and 1000', width); + throw is.invalidParameterError('width', 'integer between 1 and 65536', width); } return this; }