Skip to main content
Vulnerability Database/CVE-2026-102504

CVE-2026-102504: Tonycoz Imager DoS Vulnerability

CVE-2026-102504 is a denial of service vulnerability in Tonycoz Imager for Perl that causes process termination through malicious raw image files. This article covers technical details, affected versions, and mitigation steps.

Published:

CVE-2026-102504 Overview

CVE-2026-102504 affects the Imager Perl module versions before 1.037. The flaw resides in the i_readraw_wiol function used to read raw image files. An attacker supplying an untrusted raw_datachannels value to Imager->read() can force the process to terminate via an uncatchable exit(3) call. The root issue is missing range validation on raw_datachannels combined with an unchecked line buffer size calculation. Any Perl application that passes attacker-controlled raw image parameters to Imager is affected, including web services that process user-submitted images. The vulnerability is tracked as an integer overflow weakness [CWE-190].

Critical Impact

Remote attackers can trigger an uncatchable process exit in any Perl application that reads attacker-controlled raw image parameters through Imager, causing denial of service.

Affected Products

  • Tonycoz Imager for Perl, all versions prior to 1.037
  • Perl applications and web services embedding Imager for raw image processing
  • Downstream distributions packaging Imager through CPAN

Discovery Timeline

  • 2026-10-01 - CVE CVE-2026-102504 published to NVD
  • 2026-10-01 - Advisory posted to the OpenWall OSS Security list
  • 2026-10-08 - Last updated in NVD database

Technical Details for CVE-2026-102504

Vulnerability Analysis

The vulnerability is an integer overflow [CWE-190] in Imager's raw image reader i_readraw_wiol. The parameter raw_datachannels controls how many channels Imager reads per pixel from a raw image file. Imager documents the default as 3 and historically accepts any positive integer.

The line buffer size is computed as image width multiplied by the channel count. Without range enforcement, a negative or very large raw_datachannels value produces an arithmetic result that overflows or requests an unreasonably large allocation. When Imager's allocator fails, it does not raise a Perl exception. It calls exit(3) directly, terminating the host process.

Because exit(3) cannot be trapped by eval { } in Perl, long-running services such as PSGI workers, mod_perl, or job queues die immediately. The impact is denial of service against the entire process, not just the image operation.

Root Cause

Two defects combine. First, raw_datachannels is passed to the reader without a sanity check on sign or upper bound. Second, the buffer size calculation width * channels is not checked for arithmetic overflow before being handed to the allocator. The allocator's failure handler then uses a hard process exit rather than returning an error.

Attack Vector

An attacker supplies a crafted raw image or crafted options to any Perl code path that calls Imager->read() with user-influenced parameters. No authentication is required, and no user interaction is needed beyond submitting the image. Successful exploitation terminates the Perl interpreter.

text
- RAW:
  - validate raw_datachannels and limit to a maximum of 16
  - check raw line buffer calculation for overflow

- image creation no longer aborts the process if allocation of the
  image surface fails.

Source: GitHub Patch Commit 21b0df9

Detection Methods for CVE-2026-102504

Indicators of Compromise

  • Unexpected termination of Perl worker processes handling image uploads, with no Perl die or exception recorded in application logs.
  • Web server error logs showing abrupt child process exits during image processing requests.
  • CPAN inventories reporting Imager module versions below 1.037.

Detection Strategies

  • Inventory Perl dependencies with cpan -l or cpanm --info Imager and flag versions below 1.037.
  • Static review of application code for calls to Imager->read() that pass untrusted raw_datachannels, datachannels, xsize, or ysize values.
  • Fuzz raw image endpoints with boundary values for raw_datachannels (negative, zero, and values greater than 16) in a controlled environment.

Monitoring Recommendations

  • Alert on repeated worker crashes or restart loops in PSGI, FastCGI, or mod_perl servers that process images.
  • Capture process exit codes from Perl services and correlate against image upload activity.
  • Monitor file upload endpoints for anomalous volume targeting raw image formats.

How to Mitigate CVE-2026-102504

Immediate Actions Required

  • Upgrade Imager to version 1.037 or later on all systems running Perl image processing code.
  • Audit application code for any path that forwards client-supplied values into Imager->read() and reject non-numeric or out-of-range raw_datachannels input before the call.
  • Restart Perl worker processes after upgrading to ensure the patched module is loaded.

Patch Information

The fix is included in Imager 1.037. The patch limits raw_datachannels to a maximum of 16, validates the raw line buffer calculation for overflow, and removes the hard exit from the image allocation failure path. Review the GitHub Security Advisory GHSA-g549-r73g-x7x6 and the MetaCPAN Release Changes for Imager 1.037.

text
C<raw_datachannels> - the number of channels to read from the file.
Range: 1 to 16.  Default: 3.  Alternatively and historically spelled
C<datachannels>.

Source: GitHub Patch Commit 21b0df9

Workarounds

  • Validate and clamp raw_datachannels to the inclusive range 1 to 16 in application code before invoking Imager.
  • Reject raw image formats at the upload layer when raw processing is not required by the application.
  • Isolate image processing in short-lived subprocesses so an uncatchable exit does not take down the parent service.
bash
# Upgrade Imager via cpanm to the patched release
cpanm Imager@1.037

# Verify the installed version
perl -MImager -e 'print $Imager::VERSION, "\n"'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.