Heap Buffer Overflow in Imager by Tonycoz Affects Gallery Software
CVE-2026-102505

Currently unrated

Key Information:

Vendor

Tonycoz

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-102505?

A heap buffer overflow vulnerability exists in Imager versions prior to 1.037, specifically affecting the handling of paletted images. When using the getsamples() function with 'float' type, the library allocates insufficient buffer space for the number of pixel samples requested, leading to potential overflows if an attacker supplies a carefully crafted image. By manipulating the image's palette, an attacker can exploit this flaw, resulting in potential memory corruption and arbitrary code execution.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.