Description
Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8.

With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the original channel count. libpng expands the transparency into that extra channel, so png_read_row() fills one channel more than the buffer holds, at one byte per sample, and writes width bytes past the end of the allocation. Palette images go to read_paletted() and 16-bit images to read_direct16(), which sizes its buffer from png_get_rowbytes() and allocates enough for the expanded row.

The same reader ships bundled in the Imager distribution.

Reading an attacker-supplied PNG through Imager->read() corrupts the heap, which can crash the process.
Published: 2026-09-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Heap Corruption with potential Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Imager::File::PNG versions earlier than 1.004 for Perl contain a buffer overflow that occurs when parsing PNG files with a tRNS transparency chunk. The read_direct8() routine expands a transparency channel but still allocates a buffer based solely on the original channel count, causing libpng to write beyond the end of the allocated memory. This overflow corrupts the heap and can crash the Imager process, presenting a denial‑of‑service risk. The overflow also grants an attacker the opportunity to overwrite adjacent memory, which, while not explicitly documented, is inferred as a potential vector for more severe exploitation if the process environment permitted it.

Affected Systems

Vendors are Imager (Perl image processing library) and its bundled Imager-File-PNG distribution. Affected versions are Imager-File-PNG 1.003 and any release before 1.004, and any Imager package that includes the old bundled Imager-File-PNG prior to 1.035. Versions 1.004 of Imager-File-PNG or newer, and Imager 1.035 or newer, contain the fix.

Risk and Exploitability

The CVSS score of 9.1 indicates critical severity, while the EPSS score of less than 1% indicates a very low probability of exploitation currently. The vulnerability is not in CISA’s KEV catalog, so no mass‑distributed attacks are known. An attacker would need to supply a specially crafted PNG with a tRNS chunk that is processed by an application using the vulnerable Imager build. The denial‑of‑service impact is clearly supported. Inferred from the buffer overflow, the risk of privilege escalation or remote code execution exists if the attacker can influence the process environment or memory layout, but this has not been demonstrated. Because of the potential for denial of service on any application that loads arbitrary PNGs, the risk remains significant.

Generated by OpenCVE AI on September 22, 2026 at 21:40 UTC.

Remediation

Vendor Solution

Upgrade to Imager-File-PNG 1.004 or later, or to Imager 1.035 or later if the bundled copy is in use.


OpenCVE Recommended Actions

  • Upgrade to Imager-File-PNG 1.004 or later, or to Imager 1.035 or later if the bundled copy is in use.
  • Implement input validation or bounds checking before passing PNG data to Imager, such as rejecting PNGs with unexpected tRNS chunks or verifying that the allocated buffer matches the expanded row size.
  • Isolate image processing in a sandboxed or lower‑privileged process, or temporarily disable loading of images from untrusted sources until the patch is applied.

Generated by OpenCVE AI on September 22, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tonyc
Tonyc imager::file::png
Vendors & Products Tonyc
Tonyc imager::file::png

Fri, 18 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
References

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the original channel count. libpng expands the transparency into that extra channel, so png_read_row() fills one channel more than the buffer holds, at one byte per sample, and writes width bytes past the end of the allocation. Palette images go to read_paletted() and 16-bit images to read_direct16(), which sizes its buffer from png_get_rowbytes() and allocates enough for the expanded row. The same reader ships bundled in the Imager distribution. Reading an attacker-supplied PNG through Imager->read() corrupts the heap, which can crash the process.
Title Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8
Weaknesses CWE-787
References

Subscriptions

Tonyc Imager::file::png
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-22T18:27:56.365Z

Reserved: 2026-08-13T12:51:42.912Z

Link: CVE-2026-73639

cve-icon Vulnrichment

Updated: 2026-09-18T00:18:32.862Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:03.763

Modified: 2026-09-22T19:16:44.383

Link: CVE-2026-73639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:45:06Z

Weaknesses