CVE-2026-14454

NameCVE-2026-14454
DescriptionImager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1141959

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libimager-perl (PTS)bullseye1.012+dfsg-1vulnerable
bookworm1.019+dfsg-1vulnerable
trixie1.027+dfsg-1vulnerable
forky, sid1.033+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libimager-perlsource(unstable)1.033+dfsg-11141959

Notes

[trixie] - libimager-perl <no-dsa> (Minor issue)
[bookworm] - libimager-perl <postponed> (Minor issue; crafted EXIF data can kill the process via a failed huge allocation)
[bullseye] - libimager-perl <postponed> (Minor issue; crafted EXIF data can kill the process via a failed huge allocation)
https://lists.security.metacpan.org/cve-announce/msg/41637674/
Fixed by: https://github.com/tonycoz/imager/commit/06f01a5d0fd591259aeba589370d6888384a6b6d (v1.033)

Search for package or bug name: Reporting problems