Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <830C4C9C-D11E-40D0-A516-D259E6DD2746@stig.io>
Date: Thu, 1 Oct 2026 15:12:54 +0200
From: Stig Palmquist <stig@...g.io>
To: cve-announce@...urity.metacpan.org,
 oss-security@...ts.openwall.com
Subject: CVE-2026-102504: Imager versions before 1.037 for Perl exit the
 process reading a raw image with an out-of-range raw_datachannels value in
 i_readraw_wiol

========================================================================
CVE-2026-102504                                      CPAN Security Group
========================================================================

        CVE ID:  CVE-2026-102504

  Distribution:  Imager
      Versions:  before 1.037
      MetaCPAN:  https://metacpan.org/dist/Imager
      VCS Repo:  https://github.com/tonycoz/imager


Imager versions before 1.037 for Perl exit the process reading a raw
image with an out-of-range raw_datachannels value in i_readraw_wiol

Description
-----------
Imager versions before 1.037 for Perl exit the process reading a raw
image with an out-of-range raw_datachannels value in i_readraw_wiol.

Nothing range-checks raw_datachannels. The line buffer is sized as the
image width times the channel count with no overflow check, so a
negative or very large count requests an excessive allocation. When it
fails, Imager's allocator calls exit(3).

Passing an untrusted raw_datachannels value to Imager->read() triggers
an uncatchable exit.

Problem types
-------------
- CWE-789 Memory Allocation with Excessive Size Value
- CWE-190 Integer Overflow or Wraparound

Solutions
---------
Upgrade to Imager 1.037 or later.

References
----------
https://github.com/tonycoz/imager/security/advisories/GHSA-g549-r73g-x7x6
https://github.com/tonycoz/imager/commit/21b0df9eef1dffe1fdcd3706bfea9f1338031679.patch
https://metacpan.org/release/TONYC/Imager-1.037/changes

Timeline
--------
- 2026-09-30: Version 1.037 released with fix.

Credits
-------
ahanwate, finder


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.