CVE-2026-93019

NameCVE-2026-93019
DescriptionImager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3). Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libimager-perl (PTS)bookworm1.019+dfsg-1vulnerable
trixie1.027+dfsg-1vulnerable
forky1.036+dfsg-1fixed
sid1.037+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libimager-perlsource(unstable)1.036+dfsg-1

Notes

[trixie] - libimager-perl <no-dsa> (Minor issue)
[bookworm] - libimager-perl <postponed> (Minor issue; crafted TGA colour-map length makes the process exit)
https://lists.security.metacpan.org/cve-announce/msg/43654761/
https://github.com/tonycoz/imager/security/advisories/GHSA-p4vw-rc54-p2c2
Fixed by: https://github.com/tonycoz/imager/commit/74ed50e0625f9f51054e595bb4a8da92c1e0d571 (v1.036)

Search for package or bug name: Reporting problems