CVE-2026-102505
Description
AI Translation Available
Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.
For a paletted image, getsamples() with type 'float' allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end.
An attacker-supplied image controls the overflowing bytes through its palette.
131
Incorrect Calculation of Buffer Size
DraftCommon Consequences
Security Scopes Affected:
Integrity
Availability
Confidentiality
Potential Impacts:
Dos: Crash, Exit, Or Restart
Execute Unauthorized Code Or Commands
Read Memory
Modify Memory
Applicable Platforms
Languages:
Memory-Unsafe, C, C++
https://github.com/tonycoz/imager/commit/aae49c6be065aa467e834105c816359394a634…
https://github.com/tonycoz/imager/security/advisories/GHSA-4rx6-cgv3-fmxp
https://metacpan.org/release/TONYC/Imager-1.037/changes