{"id":"CVE-2026-102505","title":"Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.\n\nFor a paletted image, getsamples() with type \"float\" allocates a buffer of one sample per pixel and fetches every …","summary":"Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.\n\nFor a paletted image, getsamples() with type \"float\" allocates a buffer of one sample per pixel and fetches every …","severity":"none","cwe":["CWE-131"],"product":"Imager","affected":["Imager < 1.037"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:09:04.013","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102505","references":[{"url":"https://github.com/tonycoz/imager/commit/aae49c6be065aa467e834105c816359394a634db.patch","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/tonycoz/imager/security/advisories/GHSA-4rx6-cgv3-fmxp","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/TONYC/Imager-1.037/changes","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T13:44:55.840Z","slug":"CVE-2026-102505","body":"## Overview\n\nImager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.\n\nFor a paletted image, getsamples() with type \"float\" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end.\n\nAn attacker-supplied image controls the overflowing bytes through its palette.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}