๐Ÿ” CVE Alert

CVE-2026-102504

UNKNOWN 0.0

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.

CWE CWE-789 CWE-190
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new unknown vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tonycoz/imager/security/advisories/GHSA-g549-r73g-x7x6 github.com: https://github.com/tonycoz/imager/commit/21b0df9eef1dffe1fdcd3706bfea9f1338031679.patch metacpan.org: https://metacpan.org/release/TONYC/Imager-1.037/changes

Credits

ahanwate