Description
Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p.

The palette is allocated uninitialised, and only the entries a reader adds count as populated. The TGA reader stores pixel indexes without checking them against the colour map. i_gpix_p() rejects only an index greater than the count, so an index equal to it reads the first unpopulated entry, and getpixel() returns it.

i_glin_p() skips any index at or beyond the count without writing that pixel to the caller's buffer. The palette-to-RGB conversion reads each row through an uninitialised buffer, so those pixels of the converted image hold prior heap contents.

Reading an attacker-supplied image through Imager->read() and then fetching its pixels or converting it to RGB discloses process heap memory.
Published: 2026-09-18
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The flaw in Imager for Perl versions prior to 1.036 allows an attacker to read uninitialised heap memory when a paletted image contains pixel indices that exceed the defined colour map. The library’s TGA reader accepts indices that are equal to the colour map count, returning the first uninitialised palette entry; during RGB conversion it also reads from a buffer that has not been fully initialised. When an attacker supplies a crafted image and the application reads or converts it, data from the process heap can be exposed through the returned pixel values.

Affected Systems

Any system that uses Imager for Perl with a version older than 1.036 is vulnerable. This includes distributions that ship the older library, legacy Perl image‑processing applications, and bespoke scripts that depend on Imager to parse user‑supplied images. The vulnerability is active as long as the library is in use and no patch is applied.

Risk and Exploitability

The risk is limited to information disclosure; the vulnerability does not modify program state or provide execution control. The CVSS score of 5.5 reflects a moderate severity, aligning with the information‑disclosure nature of the flaw. An attacker must be able to deliver a crafted image to a running Imager instance, which can be feasible in web services or applications that accept image uploads. The EPSS score of <1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog, indicating no widespread exploitation yet. Nonetheless, because it can leak arbitrary heap contents, it should be considered a moderate‑to‑high risk for exposed services and remains exploit‑editable through simple file injection.

Generated by OpenCVE AI on September 22, 2026 at 21:39 UTC.

Remediation

Vendor Solution

Upgrade to Imager 1.036 or later.


OpenCVE Recommended Actions

  • Upgrade Imager to version 1.036 or later to eliminate the uninitialised memory read.
  • Restrict image uploads to trusted sources and validate pixel indices against the colour map before processing.
  • Disable or filter the processing of paletted or TGA images from untrusted inputs.

Generated by OpenCVE AI on September 22, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Tonycoz
Tonycoz imager
Vendors & Products Tonycoz
Tonycoz imager

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
References

Fri, 18 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader adds count as populated. The TGA reader stores pixel indexes without checking them against the colour map. i_gpix_p() rejects only an index greater than the count, so an index equal to it reads the first unpopulated entry, and getpixel() returns it. i_glin_p() skips any index at or beyond the count without writing that pixel to the caller's buffer. The palette-to-RGB conversion reads each row through an uninitialised buffer, so those pixels of the converted image hold prior heap contents. Reading an attacker-supplied image through Imager->read() and then fetching its pixels or converting it to RGB discloses process heap memory.
Title Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p
Weaknesses CWE-193
CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-22T18:27:38.610Z

Reserved: 2026-09-17T14:56:50.796Z

Link: CVE-2026-93018

cve-icon Vulnrichment

Updated: 2026-09-18T17:06:58.132Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:04.363

Modified: 2026-09-22T19:16:57.277

Link: CVE-2026-93018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:45:06Z

Weaknesses