Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read.

The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3).

Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Upgrade to Imager 1.036 or later.


Workaround

No workaround given by the vendor.

History

Fri, 18 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3). Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit.
Title Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read
Weaknesses CWE-196
CWE-789
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-18T13:58:12.083Z

Reserved: 2026-09-17T14:56:50.796Z

Link: CVE-2026-93019

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T14:19:04.480

Modified: 2026-09-18T14:19:04.480

Link: CVE-2026-93019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses