CVE-2026-102505 PUBLISHED

Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp

Assigner: CPANSec
Reserved: 29.09.2026 Published: 01.10.2026 Updated: 01.10.2026

Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.

For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end.

An attacker-supplied image controls the overflowing bytes through its palette.

Product Status

Package Collection https://cpan.org/modules
Package Name Imager
Versions Default: unaffected
  • affected from 0 to 1.037 (excl.)

Solutions

Upgrade to Imager 1.037 or later.

References

Problem Types

  • CWE-131 Incorrect Calculation of Buffer Size CWE