CVE-2026-102504

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.

  • Published Oct 1, 2026
  • CVSS 7.5 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

CVE-2026-102504 at the National Vulnerability Database