CVE-2026-102504: Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol
Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range rawdatachannels value in ireadrawwiol.
Nothing range-checks rawdatachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3).
Passing an untrusted rawdatachannels value to Imager->read() triggers an uncatchable exit.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Imagerto a version that resolves this vulnerability.Fixed in 1.037