Description
Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.

Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3).

Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.
Published: 2026-10-01
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service via uncatchable exit
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Imager for Perl occurs when a raw image file contains an out‑of‑range raw_datachannels value. The code path that reads the raw image does not enforce any bounds on raw_datachannels, so a negative or excessively large value causes an oversized buffer allocation. When the allocator cannot fulfill the request, the library calls the standard exit routine, terminating the Perl process. This failure cannot be caught or recovered by application code, resulting in a sudden denial of service. The weakness is classified as integer overflow and out‑of‑range memory allocation.

Affected Systems

Any installation of the Imager Perl module with a version earlier than 1.037 is affected. The vulnerability applies to all products that rely on Imager for rendering or processing raw image files, including web applications, image conversion utilities, or batch image processing scripts that use Imager->read() on externally supplied files. The fix is available in Imager 1.037 and later releases.

Risk and Exploitability

The lack of a CVSS score and EPSS rating means the risk is not quantified in the standard metrics, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is local or remote depending on who can supply a raw image file to the affected application; it requires the ability to control the raw_datachannels field in the image header. The impact is limited to a process crash, which can lead to service interruption but does not provide arbitrary code execution or data exfiltration. Therefore the overall risk is moderate, with a high likelihood that a system relying on Imager will be vulnerable if no mitigation is applied.

Generated by OpenCVE AI on October 1, 2026 at 15:29 UTC.

Remediation

Vendor Solution

Upgrade to Imager 1.037 or later.


OpenCVE Recommended Actions

  • Upgrade Imager to version 1.037 or later to eliminate the out‑of‑range buffer allocation bug.
  • If an upgrade cannot be performed immediately, validate or sanitize any raw_datachannels values or refuse to process raw images from untrusted sources before invoking Imager->read().
  • Run applications that rely on Imager under the least privilege principle and monitor for unexpected process exits; configure application watchdogs to restart the service promptly.

Generated by OpenCVE AI on October 1, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Tonycoz
Tonycoz imager
Vendors & Products Tonycoz
Tonycoz imager

Thu, 01 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Description Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.
Title Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol
Weaknesses CWE-190
CWE-789
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-10-01T15:08:20.353Z

Reserved: 2026-09-29T11:12:58.569Z

Link: CVE-2026-102504

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T14:17:20.080

Modified: 2026-10-01T15:09:04.013

Link: CVE-2026-102504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-789

    Memory Allocation with Excessive Size Value