Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.

Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3).

Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to Imager 1.037 or later.


Workaround

No workaround given by the vendor.

History

Thu, 01 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Description Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.
Title Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol
Weaknesses CWE-190
CWE-789
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-10-01T13:11:38.558Z

Reserved: 2026-09-29T11:12:58.569Z

Link: CVE-2026-102504

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T14:17:20.080

Modified: 2026-10-01T14:17:20.080

Link: CVE-2026-102504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses