CVE-2026-102504 PUBLISHED

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol

Assigner: CPANSec
Reserved: 29.09.2026 Published: 01.10.2026 Updated: 01.10.2026

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.

Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3).

Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.

Product Status

Package Collection https://cpan.org/modules
Package Name Imager
Versions Default: unaffected
  • affected from 0 to 1.037 (excl.)

Solutions

Upgrade to Imager 1.037 or later.

Credits

  • ahanwate finder

References

Problem Types

  • CWE-789 Memory Allocation with Excessive Size Value CWE
  • CWE-190 Integer Overflow or Wraparound CWE