CVE-2026-102504
Received Received - Intake

Imager Process Exit via Unchecked Raw Data Channels

Vulnerability report for CVE-2026-102504, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: CPANSec

Description

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Imager Perl package versions before 1.037. It involves unvalidated raw_datachannels input that can cause excessive memory allocation. When the allocation fails, the process terminates abruptly. The issue stems from missing range checks on raw_datachannels, allowing negative or very large values to trigger crashes.

Detection Guidance

To detect this vulnerability, check the version of the Imager Perl package installed on your system. Run: perl -MImager -e 'print Imager->VERSION' If the version is below 1.037, the system is vulnerable. Additionally, review applications that process untrusted raw image data, especially those using Imager's read() method with raw_datachannels parameter.

Impact Analysis

This vulnerability can cause denial of service by crashing Perl processes handling untrusted input. It is particularly dangerous in web apps, queue workers, or document processors where untrusted data might be passed into the channel count parameter. The crash occurs when memory allocation fails due to invalid channel values.

Mitigation Strategies

Immediately upgrade the Imager package to version 1.037 or later. If upgrading is not possible, restrict untrusted input to the raw_datachannels parameter to values between 1 and 16. Audit applications using Imager for raw image processing and ensure they validate input before passing it to Imager->read().

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102504. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart