Out-of-Range Vulnerability in Imager for Perl by TonyCoz
CVE-2026-102504

Currently unrated

Key Information:

Vendor

TonyCoz

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-102504?

Imager for Perl has a vulnerability that occurs when reading a raw image with an incorrect 'raw_datachannels' value. This flaw arises because there are no range checks on 'raw_datachannels', leading to potential excessive memory allocation based on image width multiplied by channel count. If a negative or an overly large value is specified, it can trigger an allocation failure, resulting in an uncatchable process exit. As a result, users passing untrusted values to Imager->read() may face crashes, compromising the application's stability. Ensure you update to version 1.037 or later to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ahanwate
.