CVE-2026-102504

NameCVE-2026-102504
DescriptionImager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libimager-perl (PTS)bookworm1.019+dfsg-1vulnerable
trixie1.027+dfsg-1vulnerable
forky, sid1.036+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libimager-perlsource(unstable)(unfixed)

Notes

https://lists.security.metacpan.org/cve-announce/msg/43998314/
https://github.com/tonycoz/imager/security/advisories/GHSA-g549-r73g-x7x6
Fixed by: https://github.com/tonycoz/imager/commit/21b0df9eef1dffe1fdcd3706bfea9f1338031679 (v1.037)

Search for package or bug name: Reporting problems