[med-svn] [Git][med-team/ants][master] 2 commits: Fix segfaults in ANTS tools on malformed command-line input (Closes: #715579, ...

Andreas Tille (@tille) gitlab at salsa.debian.org
Thu Sep 24 15:20:17 BST 2026



Andreas Tille pushed to branch master at Debian Med / ants


Commits:
f97726eb by Andreas Tille at 2026-09-24T14:30:16+02:00
Fix segfaults in ANTS tools on malformed command-line input (Closes: #715579, #715580, #715581, #715582, #715583)

Add fix_mayhem_crashes.patch hardening ANTS, ANTSIntegrateVectorField,
ANTSUseDeformationFieldToGetAffineTransform,
ANTSUseLandmarkImagesToGetAffineTransform and Atropos against
malformed input that previously caused segmentation faults. Add an
autopkgtest regression test covering the crash inputs.

- - - - -
a0fef3e8 by Andreas Tille at 2026-09-24T15:41:42+02:00
Upload to unstable

- - - - -


5 changed files:

- debian/changelog
- + debian/patches/fix_mayhem_crashes.patch
- debian/patches/series
- + debian/tests/control
- + debian/tests/mayhem-crash-inputs


Changes:

=====================================
debian/changelog
=====================================
@@ -1,4 +1,4 @@
-ants (2.6.5+dfsg-1) UNRELEASED; urgency=medium
+ants (2.6.5+dfsg-1) unstable; urgency=medium
 
   * Team upload.
   * d/copyright: Update Source
@@ -10,8 +10,14 @@ ants (2.6.5+dfsg-1) UNRELEASED; urgency=medium
   * Set upstream metadata fields: Bug-Database, Repository-Browse.
   * d/salsa-ci.yml: i386 is implicitly excluded by Build-Depends:
     libinsighttoolkit5-dev which exists only on amd64
-
- -- Andreas Tille <tille at debian.org>  Wed, 02 Sep 2026 16:31:45 +0200
+  * Fix segfaults in ANTS, ANTSIntegrateVectorField,
+    ANTSUseDeformationFieldToGetAffineTransform,
+    ANTSUseLandmarkImagesToGetAffineTransform and Atropos when run with
+    malformed command-line input
+    Closes: #715579, #715580, #715581, #715582, #715583
+  * Add autopkgtest regression test for the above crashes
+
+ -- Andreas Tille <tille at debian.org>  Thu, 24 Sep 2026 14:32:12 +0200
 
 ants (2.6.4+dfsg-1) unstable; urgency=medium
 


=====================================
debian/patches/fix_mayhem_crashes.patch
=====================================
@@ -0,0 +1,99 @@
+Description: Fix crashes (segfaults) triggered by malformed command-line input
+ Several ANTs tools crash with a segmentation fault (exit status 139) when
+ given malformed or incomplete command-line arguments, e.g. non-existent
+ input image files or a missing required argument.  These were reported by
+ the Mayhem fuzzing project in Debian bugs #715579, #715580, #715581,
+ #715582 and #715583 and are still reproducible with the current release.
+ .
+  * ANTS: abort registration cleanly when no image metric was specified
+    (previously dereferenced a null function pointer for the missing
+    "output-naming" option).
+  * ANTSIntegrateVectorField: check that the input image can be read before
+    dereferencing the image IO object.
+  * ANTSUseDeformationFieldToGetAffineTransform: require the rigid/affine
+    argument, which was previously read without checking argc.
+  * ANTSUseLandmarkImagesToGetAffineTransform: check that the input image
+    can be read before dereferencing the image IO object.
+  * Atropos: check that the input image can be read before dereferencing
+    the image IO object.
+Author: Debian Med Packaging Team <debian-med-packaging at lists.alioth.debian.org>
+Forwarded: https://github.com/ANTsX/ANTs
+Last-Update: 2026-09-24
+
+diff --git a/Examples/ANTSIntegrateVectorField.cxx b/Examples/ANTSIntegrateVectorField.cxx
+index c76772d8..a2c4e3e5 100644
+--- a/Examples/ANTSIntegrateVectorField.cxx
++++ b/Examples/ANTSIntegrateVectorField.cxx
+@@ -499,6 +499,11 @@ ANTSIntegrateVectorField(std::vector<std::string> args, std::ostream * /*out_str
+ 
+   std::string               ifn = std::string(argv[1]);
+   itk::ImageIOBase::Pointer imageIO = itk::ImageIOFactory::CreateImageIO(ifn.c_str(), itk::IOFileModeEnum::ReadMode);
++  if (imageIO.IsNull())
++  {
++    std::cerr << "Cannot read input image: " << ifn << std::endl;
++    return EXIT_FAILURE;
++  }
+   imageIO->SetFileName(ifn.c_str());
+   imageIO->ReadImageInformation();
+   unsigned int dim = imageIO->GetNumberOfDimensions();
+diff --git a/Examples/ANTSUseDeformationFieldToGetAffineTransform.cxx b/Examples/ANTSUseDeformationFieldToGetAffineTransform.cxx
+index 267d1576..f745467b 100644
+--- a/Examples/ANTSUseDeformationFieldToGetAffineTransform.cxx
++++ b/Examples/ANTSUseDeformationFieldToGetAffineTransform.cxx
+@@ -463,7 +463,7 @@ ANTSUseDeformationFieldToGetAffineTransform(std::vector<std::string> args, std::
+ 
+   // antscout->set_stream( out_stream );
+ 
+-  if (argc < 3)
++  if (argc < 4)
+   {
+     std::cout << "Usage:   " << argv[0]
+               << " zzzWarp.nii.gz load_ratio(ex: 0.01) [rigid | affine] OutAffine.txt [mask.nii.gz]" << std::endl;
+diff --git a/Examples/ANTSUseLandmarkImagesToGetAffineTransform.cxx b/Examples/ANTSUseLandmarkImagesToGetAffineTransform.cxx
+index baf69cf1..5251f341 100644
+--- a/Examples/ANTSUseLandmarkImagesToGetAffineTransform.cxx
++++ b/Examples/ANTSUseLandmarkImagesToGetAffineTransform.cxx
+@@ -431,6 +431,11 @@ ANTSUseLandmarkImagesToGetAffineTransform(std::vector<std::string> args, std::os
+   // Get the image dimension
+   std::string               fn = std::string(argv[1]);
+   itk::ImageIOBase::Pointer imageIO = itk::ImageIOFactory::CreateImageIO(fn.c_str(), itk::IOFileModeEnum::ReadMode);
++  if (imageIO.IsNull())
++  {
++    std::cerr << "Cannot read input image: " << fn << std::endl;
++    return EXIT_FAILURE;
++  }
+   imageIO->SetFileName(fn.c_str());
+   imageIO->ReadImageInformation();
+ 
+diff --git a/Examples/Atropos.cxx b/Examples/Atropos.cxx
+index 76d08bd1..a44ad150 100644
+--- a/Examples/Atropos.cxx
++++ b/Examples/Atropos.cxx
+@@ -1709,6 +1709,11 @@ Atropos(std::vector<std::string> args, std::ostream * /*out_stream = nullptr */)
+     }
+     itk::ImageIOBase::Pointer imageIO =
+       itk::ImageIOFactory::CreateImageIO(filename.c_str(), itk::IOFileModeEnum::ReadMode);
++    if (imageIO.IsNull())
++    {
++      std::cerr << "Cannot read input image: " << filename << std::endl;
++      return EXIT_FAILURE;
++    }
+     dimension = imageIO->GetNumberOfDimensions();
+   }
+ 
+diff --git a/ImageRegistration/itkPICSLAdvancedNormalizationToolKit.hxx b/ImageRegistration/itkPICSLAdvancedNormalizationToolKit.hxx
+index cd4abcf7..e5836ffe 100644
+--- a/ImageRegistration/itkPICSLAdvancedNormalizationToolKit.hxx
++++ b/ImageRegistration/itkPICSLAdvancedNormalizationToolKit.hxx
+@@ -123,6 +123,11 @@ PICSLAdvancedNormalizationToolKit<TDimension, TReal>::RunRegistration()
+ {
+   /** parse the command line and get input objects */
+   this->ReadImagesAndMetrics();
++  if (this->m_SimilarityMetrics.empty())
++  {
++    itkExceptionMacro("No image metrics defined.  Please specify at least one metric "
++                      "using the -m option (e.g. -m MI[fixed.nii.gz,moving.nii.gz,1,32]).");
++  }
+   //    std::exception();
+   /** initializes the transformation model and the optimizer */
+   this->InitializeTransformAndOptimizer();


=====================================
debian/patches/series
=====================================
@@ -3,3 +3,4 @@ no_external_data.patch
 linker_flags.patch
 spelling.patch
 follow_rpath.patch
+fix_mayhem_crashes.patch


=====================================
debian/tests/control
=====================================
@@ -0,0 +1,3 @@
+Tests: mayhem-crash-inputs
+Restrictions: allow-stderr
+Depends: @


=====================================
debian/tests/mayhem-crash-inputs
=====================================
@@ -0,0 +1,45 @@
+#!/bin/sh
+# Regression test for the [Mayhem] crash bugs (Debian bugs #715579, #715580,
+# #715581, #715582 and #715583).  These reproduce the malformed command
+# lines found by the Mayhem fuzzing project: each ANTs tool is fed a
+# command line with non-existent input files and/or missing arguments.  The
+# tools must not crash (segmentation fault, exit status 139); they are
+# expected to report an error and exit cleanly (possibly with a non-zero
+# status) instead.
+set -e
+
+BINDIR=/usr/lib/ants
+
+run_case() {
+  name="$1"
+  tool="$2"
+  args="$3"
+  echo "Running $name (tool: $tool, args: $args) ..."
+  set +e
+  eval "env -i MALLOC_CHECK_=0 '$BINDIR/$tool' $args" </dev/null >/tmp/mayhem-$name.out 2>&1
+  rc=$?
+  set -e
+  if [ "$rc" -ge 128 ]; then
+    echo "  FAIL: $tool was killed by a signal (status $rc)"
+    sed 's/^/    /' /tmp/mayhem-$name.out | head -10
+    return 1
+  else
+    echo "  OK: $tool handled $name without crashing (status $rc)"
+    return 0
+  fi
+}
+
+fail=0
+run_case ANTS ANTS "'2' 'A' 'A'" || fail=1
+run_case ANTSIntegrateVectorField ANTSIntegrateVectorField "'AAAAAAAAAA' 'AA' 'AA'" || fail=1
+run_case ANTSUseDeformationFieldToGetAffineTransform \
+  ANTSUseDeformationFieldToGetAffineTransform "' AAAAAAAAA' '.0'" || fail=1
+run_case ANTSUseLandmarkImagesToGetAffineTransform \
+  ANTSUseLandmarkImagesToGetAffineTransform "'AAAAAAAAAA' 'AA' 'AA'" || fail=1
+run_case Atropos Atropos "'-a'" || fail=1
+
+if [ "$fail" -ne 0 ]; then
+  echo "At least one ANTs tool still crashes on malformed input."
+  exit 1
+fi
+echo "All malformed-input testcases handled without crashing."



View it on GitLab: https://salsa.debian.org/med-team/ants/-/compare/467a65bb6dcf9af72b615a9659de9a1a91e1cdb5...a0fef3e8eee855a118d907574f879b8502731f54

-- 
View it on GitLab: https://salsa.debian.org/med-team/ants/-/compare/467a65bb6dcf9af72b615a9659de9a1a91e1cdb5...a0fef3e8eee855a118d907574f879b8502731f54
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-med-commit/attachments/20260924/26ca26ab/attachment-0001.htm>


More information about the debian-med-commit mailing list