Tk Source Code

View Ticket
Login
Ticket UUID: fef61fae66688eefc276a11c53b545766edb6a47
Title: ImgPhotoCmd(): missing validity checks in case PHOTO_DATA
Type: Bug Version:
Submitter: chrstphrchvz Created on: 2023-04-22 14:48:46
Subsystem: 41. Photo Images Assigned To: jan.nijtmans
Priority: 5 Medium Severity: Minor
Status: Closed Last Modified: 2026-10-04 20:20:36
Resolution: Fixed Closed By: jan.nijtmans
    Closed on: 2026-10-04 20:20:36
Description:

See François’ comment below. Original description:

In Tk 8.7, imgListFormat-1.3 triggers a -fsanitize=pointer-overflow error:

generic/tkImgPhoto.c:4299:24: runtime error: applying zero offset to null pointer

…i.e. blockPtr->pixelPtr is NULL. However, I believe the fix for this likely also applies to 8.6.

User Comments: jan.nijtmans added on 2026-10-04 20:20:36:

Fixed in [e072bf31868dab1b|trunk] and core-9-0-branch

Closing. Many thanks!


serhiy.storchaka added on 2026-09-18 11:00:41:

The NULL pointer part was fixed in [d93d961dd4]. The GIF and PNG writers (and the PPM reader and writer) ignored the -format list, so unknown options were silently accepted. They now report bad format option "-foobar": no options allowed, like the default handler. Fixed on branch photo-format-options-check in [1534f184c2].


chrstphrchvz added on 2025-08-02 09:52:41:

In favor of designating this ticket for issues in François’ broader analysis, I have split off the original issue with a simpler description as [d93d961dd4].


fvogel added on 2023-04-23 17:09:32:

Thanks, I can reproduce on macOS.

In ImgPhotoCmd(), case PHOTO_DATA, there is no validity check for the spelling of the suboption coming with the given (in the present case: "default") image format handler. Such check des not happen before calling ImgGetPhoto() at tkImgPhoto.c:886, which is the call that triggers the reported runtime error. The error checking is performed just a bit later, when calling the stringWriteProc, which checks the suboptions for the given format.

At first sight, a correct fix would be to introduce this error checking before calling ImgGetPhoto() in ImgPhotoCmd(), instead of letting this happen later in the stringWriteProc.

Another incarnation of the same issue is for example (further than the sanitize runtime error, note the missing error message against {gif -foobar}):

% image create photo photo1
photo1
% photo1 data -format {gif -foobar}
/Volumes/Users/fvogel/Documents/tcltk/fossil/tk/unix/../generic/tkImgGIF.c:2027:44: runtime error: applying non-zero offset 2 to null pointer
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior /Volumes/Users/fvogel/Documents/tcltk/fossil/tk/unix/../generic/tkImgGIF.c:2027:44 in
GIF89a�ÙÙÙÿÿÿÿÿÿÿÿÿ!ù,|;

While an error checking for the spelling of the suboption exists for "default" (despite too late in the code flow), there is no such checking for the suboptions of the "gif" or "png" image format handlers. This should be added. That said, the "png" image handler however does not trigger any sanitizer runtime error. Finally, the "svg" format handler however is totally fine (no sanitizer runtime error, and the bogus subotpion name is correctly catched).