---
id: CVE-2026-102504
title: >-
  Imager versions before 1.037 for Perl exit the process reading a raw image
  with an out-of-range raw_datachannels value in i_readraw_wiol.


  Nothing range-checks raw_datachannels
summary: >-
  Imager versions before 1.037 for Perl exit the process reading a raw image
  with an out-of-range raw_datachannels value in i_readraw_wiol.


  Nothing range-checks raw_datachannels. The line buffer is sized as the image
  width times the chann…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-190
  - CWE-789
product: Imager
affected:
  - Imager < 1.037
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T20:17:21.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102504'
references:
  - url: >-
      https://github.com/tonycoz/imager/commit/21b0df9eef1dffe1fdcd3706bfea9f1338031679.patch
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'https://github.com/tonycoz/imager/security/advisories/GHSA-g549-r73g-x7x6'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'https://metacpan.org/release/TONYC/Imager-1.037/changes'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'http://www.openwall.com/lists/oss-security/2026/10/01/9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-102504.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-102504'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-102504'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-01T19:31:27.061525Z'
ingestedAt: '2026-10-01T13:44:55.840Z'
vendor: Red Hat
---

## Overview

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.

Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3).

Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-10-01 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-102504.json)
