Sceawere

Vulnerability Detail

CVE-2026-102505UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Imager Heap Buffer Overflow

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
1d ago
Vendor
—
Product
N/A
Attack Type
CWE-131 Incorrect Calculation of Buffer Size
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp. For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end. An attacker-supplied image controls the overflowing bytes through its palette.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-01T14:17:20.237Z",
  "pubdate": "2026-10-01T14:17:20.237Z",
  "executiveSummary": "A heap-based buffer overflow vulnerability exists in the Imager Perl module, specifically within the i_gsampf_fp function, affecting all versions prior to 1.037.\nThe vulnerability occurs during the processing of paletted images when the getsamples() method is invoked with a 'float' sample type.\nBy manipulating image data, a remote attacker can trigger an out-of-bounds write operation, potentially leading to arbitrary code execution, application crashes, or memory corruption.\nThe impact is significant, as successful exploitation allows for heap manipulation using attacker-controlled bytes sourced directly from the image palette.\nThe vulnerability does not require authentication to trigger if the application processes externally provided image files, making it a critical risk for systems handling untrusted user uploads.\nRemediation requires updating the Imager library to version 1.037 or later.",
  "technicalDetails": "The root cause of this heap buffer overflow resides in the memory allocation logic of i_gsampf_fp within the Imager library. When processing paletted images via the getsamples() method with the type set to 'float', the function improperly calculates the required heap buffer size.\nSpecifically, the implementation allocates a buffer based on the assumption of one sample per pixel. However, the internal logic proceeds to fetch every requested channel for each pixel into this single-sample-sized buffer. When a request specifies more than one channel, the subsequent write operations exceed the allocated buffer boundary, leading to an out-of-bounds heap write.\nThe attack flow begins when an application uses the Imager library to perform image operations on a malicious, attacker-crafted file. The attacker defines a custom palette within the image structure to control the specific byte values written to the heap during the overflow. Because the palette content is entirely controlled by the attacker, they can influence the data written past the end of the buffer.\nThis vulnerability is triggered through the standard processing pipeline of the Imager module. No complex privilege requirements or authentication states are needed to initiate the overflow, provided the attacker can submit an image to the vulnerable application. The lack of proper bounds checking on the destination buffer size relative to the number of channels being processed by i_gsampf_fp creates a direct path for memory corruption.\nExploitation involves carefully shaping the input file's palette to overwrite adjacent heap metadata or function pointers. By corrupting the heap structure, an attacker may achieve control over the application's instruction pointer, facilitating arbitrary code execution under the context of the user running the Perl process. Even in the absence of full code execution, the ability to overwrite critical heap objects provides the attacker with a primitive to compromise the integrity of the process memory space. The vulnerability is inherently tied to the processing of paletted imagery, and any system utilizing Imager to perform float-based sampling on such images is susceptible to this attack vector."
}
CVE-2026-102505: Imager Heap Buffer Overflow (MEDIUM Severity, CVSS: 6.3) | Sceawere