Sceawere

Vulnerability Detail

CVE-2026-102504UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Imager Denial of Service Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
1d ago
Vendor
—
Product
N/A
Attack Type
CWE-789 Memory Allocation with Excessive Size Value
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-01T14:17:20.080Z",
  "pubdate": "2026-10-01T14:17:20.080Z",
  "executiveSummary": "A critical availability vulnerability exists in the Imager module for Perl, affecting versions prior to 1.037. The vulnerability is classified as an improper input validation flaw leading to an uncatchable process termination (Denial of Service).\nThe root cause resides in the i_readraw_wiol function, which fails to perform bounds checking on the raw_datachannels parameter provided during the raw image reading process. Consequently, an attacker providing a maliciously crafted raw_datachannels value can trigger an excessive memory allocation request.\nWhen the underlying memory allocator fails to fulfill this request, Imager initiates a hard process exit, resulting in the immediate termination of the host application. This vulnerability does not require authentication or elevated privileges, as it can be triggered through any interface that permits the processing of raw image data. The impact is significant for services relying on Imager for image processing, as it allows unauthenticated remote attackers to disrupt service availability by crashing the process. Remediation requires upgrading to version 1.037 or later, where input validation logic has been implemented to constrain the parameter range.",
  "technicalDetails": "The vulnerability is situated within the i_readraw_wiol function, which is responsible for parsing raw image headers and data streams within the Imager library. During the processing of a raw image, the library extracts a variable designated as raw_datachannels, which dictates the number of channels per pixel. This value is used to calculate the size of the line buffer necessary for image data storage.\nThe fundamental flaw is a lack of range verification for the raw_datachannels variable. The library performs a calculation—typically image width multiplied by the channel count—to determine the allocation size for the line buffer. Because raw_datachannels is not subjected to sanitization or boundary checks, an attacker can supply an extreme, negative, or near-overflow integer value. If the resulting calculation exceeds the available address space or the system's memory limits, the allocation request fails.\nUpon a failed allocation, Imager's internal memory management routines invoke exit(3), causing an immediate and non-recoverable termination of the entire Perl process. Because this exit occurs within the library's internal error handling routine, the parent Perl application cannot use eval{} blocks or signal handlers to trap the termination, rendering the crash unavoidable from the perspective of the calling code.\nExploitation is straightforward: an attacker provides an untrusted raw image file or stream to the Imager->read() method. By manipulating the raw_datachannels metadata field in the input, the attacker forces the library into the vulnerable code path. The process is terminated immediately upon the library's attempt to allocate the buffer. This requires no authentication and is effective against any system that parses user-supplied raw image data using vulnerable versions of Imager. The impact is restricted to a Denial of Service (DoS) as the vulnerability causes process exhaustion rather than code execution or privilege escalation. The scope of exposure includes any web application or service that utilizes Imager to process raw image inputs from external sources, making it a viable target for service disruption attacks."
}
CVE-2026-102504: Imager Denial of Service Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere