CVE-2026-14454

NameCVE-2026-14454
DescriptionImager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1141959

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libimager-perl (PTS)bullseye1.012+dfsg-1vulnerable
bookworm1.019+dfsg-1vulnerable
trixie1.027+dfsg-1vulnerable
forky, sid1.032+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libimager-perlsource(unstable)(unfixed)1141959

Notes

[trixie] - libimager-perl <no-dsa> (Minor issue)
https://lists.security.metacpan.org/cve-announce/msg/41637674/
Fixed by: https://github.com/tonycoz/imager/commit/06f01a5d0fd591259aeba589370d6888384a6b6d (v1.033)

Search for package or bug name: Reporting problems