[med-svn] [Git][med-team/ants][master] 2 commits: Fix segfaults in ANTS tools on malformed command-line input (Closes: #715579, ...
Andreas Tille (@tille)
gitlab at salsa.debian.org
Thu Sep 24 15:20:17 BST 2026
Andreas Tille pushed to branch master at Debian Med / ants
Commits:
f97726eb by Andreas Tille at 2026-09-24T14:30:16+02:00
Fix segfaults in ANTS tools on malformed command-line input (Closes: #715579, #715580, #715581, #715582, #715583)
Add fix_mayhem_crashes.patch hardening ANTS, ANTSIntegrateVectorField,
ANTSUseDeformationFieldToGetAffineTransform,
ANTSUseLandmarkImagesToGetAffineTransform and Atropos against
malformed input that previously caused segmentation faults. Add an
autopkgtest regression test covering the crash inputs.
- - - - -
a0fef3e8 by Andreas Tille at 2026-09-24T15:41:42+02:00
Upload to unstable
- - - - -
5 changed files:
- debian/changelog
- + debian/patches/fix_mayhem_crashes.patch
- debian/patches/series
- + debian/tests/control
- + debian/tests/mayhem-crash-inputs
Changes:
=====================================
debian/changelog
=====================================
@@ -1,4 +1,4 @@
-ants (2.6.5+dfsg-1) UNRELEASED; urgency=medium
+ants (2.6.5+dfsg-1) unstable; urgency=medium
* Team upload.
* d/copyright: Update Source
@@ -10,8 +10,14 @@ ants (2.6.5+dfsg-1) UNRELEASED; urgency=medium
* Set upstream metadata fields: Bug-Database, Repository-Browse.
* d/salsa-ci.yml: i386 is implicitly excluded by Build-Depends:
libinsighttoolkit5-dev which exists only on amd64
-
- -- Andreas Tille <tille at debian.org> Wed, 02 Sep 2026 16:31:45 +0200
+ * Fix segfaults in ANTS, ANTSIntegrateVectorField,
+ ANTSUseDeformationFieldToGetAffineTransform,
+ ANTSUseLandmarkImagesToGetAffineTransform and Atropos when run with
+ malformed command-line input
+ Closes: #715579, #715580, #715581, #715582, #715583
+ * Add autopkgtest regression test for the above crashes
+
+ -- Andreas Tille <tille at debian.org> Thu, 24 Sep 2026 14:32:12 +0200
ants (2.6.4+dfsg-1) unstable; urgency=medium
=====================================
debian/patches/fix_mayhem_crashes.patch
=====================================
@@ -0,0 +1,99 @@
+Description: Fix crashes (segfaults) triggered by malformed command-line input
+ Several ANTs tools crash with a segmentation fault (exit status 139) when
+ given malformed or incomplete command-line arguments, e.g. non-existent
+ input image files or a missing required argument. These were reported by
+ the Mayhem fuzzing project in Debian bugs #715579, #715580, #715581,
+ #715582 and #715583 and are still reproducible with the current release.
+ .
+ * ANTS: abort registration cleanly when no image metric was specified
+ (previously dereferenced a null function pointer for the missing
+ "output-naming" option).
+ * ANTSIntegrateVectorField: check that the input image can be read before
+ dereferencing the image IO object.
+ * ANTSUseDeformationFieldToGetAffineTransform: require the rigid/affine
+ argument, which was previously read without checking argc.
+ * ANTSUseLandmarkImagesToGetAffineTransform: check that the input image
+ can be read before dereferencing the image IO object.
+ * Atropos: check that the input image can be read before dereferencing
+ the image IO object.
+Author: Debian Med Packaging Team <debian-med-packaging at lists.alioth.debian.org>
+Forwarded: https://github.com/ANTsX/ANTs
+Last-Update: 2026-09-24
+
+diff --git a/Examples/ANTSIntegrateVectorField.cxx b/Examples/ANTSIntegrateVectorField.cxx
+index c76772d8..a2c4e3e5 100644
+--- a/Examples/ANTSIntegrateVectorField.cxx
++++ b/Examples/ANTSIntegrateVectorField.cxx
+@@ -499,6 +499,11 @@ ANTSIntegrateVectorField(std::vector<std::string> args, std::ostream * /*out_str
+
+ std::string ifn = std::string(argv[1]);
+ itk::ImageIOBase::Pointer imageIO = itk::ImageIOFactory::CreateImageIO(ifn.c_str(), itk::IOFileModeEnum::ReadMode);
++ if (imageIO.IsNull())
++ {
++ std::cerr << "Cannot read input image: " << ifn << std::endl;
++ return EXIT_FAILURE;
++ }
+ imageIO->SetFileName(ifn.c_str());
+ imageIO->ReadImageInformation();
+ unsigned int dim = imageIO->GetNumberOfDimensions();
+diff --git a/Examples/ANTSUseDeformationFieldToGetAffineTransform.cxx b/Examples/ANTSUseDeformationFieldToGetAffineTransform.cxx
+index 267d1576..f745467b 100644
+--- a/Examples/ANTSUseDeformationFieldToGetAffineTransform.cxx
++++ b/Examples/ANTSUseDeformationFieldToGetAffineTransform.cxx
+@@ -463,7 +463,7 @@ ANTSUseDeformationFieldToGetAffineTransform(std::vector<std::string> args, std::
+
+ // antscout->set_stream( out_stream );
+
+- if (argc < 3)
++ if (argc < 4)
+ {
+ std::cout << "Usage: " << argv[0]
+ << " zzzWarp.nii.gz load_ratio(ex: 0.01) [rigid | affine] OutAffine.txt [mask.nii.gz]" << std::endl;
+diff --git a/Examples/ANTSUseLandmarkImagesToGetAffineTransform.cxx b/Examples/ANTSUseLandmarkImagesToGetAffineTransform.cxx
+index baf69cf1..5251f341 100644
+--- a/Examples/ANTSUseLandmarkImagesToGetAffineTransform.cxx
++++ b/Examples/ANTSUseLandmarkImagesToGetAffineTransform.cxx
+@@ -431,6 +431,11 @@ ANTSUseLandmarkImagesToGetAffineTransform(std::vector<std::string> args, std::os
+ // Get the image dimension
+ std::string fn = std::string(argv[1]);
+ itk::ImageIOBase::Pointer imageIO = itk::ImageIOFactory::CreateImageIO(fn.c_str(), itk::IOFileModeEnum::ReadMode);
++ if (imageIO.IsNull())
++ {
++ std::cerr << "Cannot read input image: " << fn << std::endl;
++ return EXIT_FAILURE;
++ }
+ imageIO->SetFileName(fn.c_str());
+ imageIO->ReadImageInformation();
+
+diff --git a/Examples/Atropos.cxx b/Examples/Atropos.cxx
+index 76d08bd1..a44ad150 100644
+--- a/Examples/Atropos.cxx
++++ b/Examples/Atropos.cxx
+@@ -1709,6 +1709,11 @@ Atropos(std::vector<std::string> args, std::ostream * /*out_stream = nullptr */)
+ }
+ itk::ImageIOBase::Pointer imageIO =
+ itk::ImageIOFactory::CreateImageIO(filename.c_str(), itk::IOFileModeEnum::ReadMode);
++ if (imageIO.IsNull())
++ {
++ std::cerr << "Cannot read input image: " << filename << std::endl;
++ return EXIT_FAILURE;
++ }
+ dimension = imageIO->GetNumberOfDimensions();
+ }
+
+diff --git a/ImageRegistration/itkPICSLAdvancedNormalizationToolKit.hxx b/ImageRegistration/itkPICSLAdvancedNormalizationToolKit.hxx
+index cd4abcf7..e5836ffe 100644
+--- a/ImageRegistration/itkPICSLAdvancedNormalizationToolKit.hxx
++++ b/ImageRegistration/itkPICSLAdvancedNormalizationToolKit.hxx
+@@ -123,6 +123,11 @@ PICSLAdvancedNormalizationToolKit<TDimension, TReal>::RunRegistration()
+ {
+ /** parse the command line and get input objects */
+ this->ReadImagesAndMetrics();
++ if (this->m_SimilarityMetrics.empty())
++ {
++ itkExceptionMacro("No image metrics defined. Please specify at least one metric "
++ "using the -m option (e.g. -m MI[fixed.nii.gz,moving.nii.gz,1,32]).");
++ }
+ // std::exception();
+ /** initializes the transformation model and the optimizer */
+ this->InitializeTransformAndOptimizer();
=====================================
debian/patches/series
=====================================
@@ -3,3 +3,4 @@ no_external_data.patch
linker_flags.patch
spelling.patch
follow_rpath.patch
+fix_mayhem_crashes.patch
=====================================
debian/tests/control
=====================================
@@ -0,0 +1,3 @@
+Tests: mayhem-crash-inputs
+Restrictions: allow-stderr
+Depends: @
=====================================
debian/tests/mayhem-crash-inputs
=====================================
@@ -0,0 +1,45 @@
+#!/bin/sh
+# Regression test for the [Mayhem] crash bugs (Debian bugs #715579, #715580,
+# #715581, #715582 and #715583). These reproduce the malformed command
+# lines found by the Mayhem fuzzing project: each ANTs tool is fed a
+# command line with non-existent input files and/or missing arguments. The
+# tools must not crash (segmentation fault, exit status 139); they are
+# expected to report an error and exit cleanly (possibly with a non-zero
+# status) instead.
+set -e
+
+BINDIR=/usr/lib/ants
+
+run_case() {
+ name="$1"
+ tool="$2"
+ args="$3"
+ echo "Running $name (tool: $tool, args: $args) ..."
+ set +e
+ eval "env -i MALLOC_CHECK_=0 '$BINDIR/$tool' $args" </dev/null >/tmp/mayhem-$name.out 2>&1
+ rc=$?
+ set -e
+ if [ "$rc" -ge 128 ]; then
+ echo " FAIL: $tool was killed by a signal (status $rc)"
+ sed 's/^/ /' /tmp/mayhem-$name.out | head -10
+ return 1
+ else
+ echo " OK: $tool handled $name without crashing (status $rc)"
+ return 0
+ fi
+}
+
+fail=0
+run_case ANTS ANTS "'2' 'A' 'A'" || fail=1
+run_case ANTSIntegrateVectorField ANTSIntegrateVectorField "'AAAAAAAAAA' 'AA' 'AA'" || fail=1
+run_case ANTSUseDeformationFieldToGetAffineTransform \
+ ANTSUseDeformationFieldToGetAffineTransform "' AAAAAAAAA' '.0'" || fail=1
+run_case ANTSUseLandmarkImagesToGetAffineTransform \
+ ANTSUseLandmarkImagesToGetAffineTransform "'AAAAAAAAAA' 'AA' 'AA'" || fail=1
+run_case Atropos Atropos "'-a'" || fail=1
+
+if [ "$fail" -ne 0 ]; then
+ echo "At least one ANTs tool still crashes on malformed input."
+ exit 1
+fi
+echo "All malformed-input testcases handled without crashing."
View it on GitLab: https://salsa.debian.org/med-team/ants/-/compare/467a65bb6dcf9af72b615a9659de9a1a91e1cdb5...a0fef3e8eee855a118d907574f879b8502731f54
--
View it on GitLab: https://salsa.debian.org/med-team/ants/-/compare/467a65bb6dcf9af72b615a9659de9a1a91e1cdb5...a0fef3e8eee855a118d907574f879b8502731f54
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-med-commit/attachments/20260924/26ca26ab/attachment-0001.htm>
More information about the debian-med-commit
mailing list