{"id":"CVE-2026-102504","title":"Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.\n\nNothing range-checks raw_datachannels","summary":"Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.\n\nNothing range-checks raw_datachannels. The line buffer is sized as the image width times the chann…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-190","CWE-789"],"product":"Imager","affected":["Imager < 1.037"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T20:17:21.087","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102504","references":[{"url":"https://github.com/tonycoz/imager/commit/21b0df9eef1dffe1fdcd3706bfea9f1338031679.patch","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/tonycoz/imager/security/advisories/GHSA-g549-r73g-x7x6","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/TONYC/Imager-1.037/changes","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/01/9","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-102504.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-102504"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-102504"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-01T19:31:27.061525Z"},"ingestedAt":"2026-10-01T13:44:55.840Z","vendor":"Red Hat","slug":"CVE-2026-102504","body":"## Overview\n\nImager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.\n\nNothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3).\n\nPassing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-10-01 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-102504.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":214666,"id":"CVE-2026-102504","ts":1790884802159,"field":"cvss","old":null,"new":"7.5"},{"seq":214665,"id":"CVE-2026-102504","ts":1790884802159,"field":"severity","old":"none","new":"high"}]}