CVE-2026-102504 Overview
CVE-2026-102504 affects the Imager Perl module versions before 1.037. The flaw resides in the i_readraw_wiol function used to read raw image files. An attacker supplying an untrusted raw_datachannels value to Imager->read() can force the process to terminate via an uncatchable exit(3) call. The root issue is missing range validation on raw_datachannels combined with an unchecked line buffer size calculation. Any Perl application that passes attacker-controlled raw image parameters to Imager is affected, including web services that process user-submitted images. The vulnerability is tracked as an integer overflow weakness [CWE-190].
Critical Impact
Remote attackers can trigger an uncatchable process exit in any Perl application that reads attacker-controlled raw image parameters through Imager, causing denial of service.
Affected Products
- Tonycoz Imager for Perl, all versions prior to 1.037
- Perl applications and web services embedding Imager for raw image processing
- Downstream distributions packaging Imager through CPAN
Discovery Timeline
- 2026-10-01 - CVE CVE-2026-102504 published to NVD
- 2026-10-01 - Advisory posted to the OpenWall OSS Security list
- 2026-10-08 - Last updated in NVD database
Technical Details for CVE-2026-102504
Vulnerability Analysis
The vulnerability is an integer overflow [CWE-190] in Imager's raw image reader i_readraw_wiol. The parameter raw_datachannels controls how many channels Imager reads per pixel from a raw image file. Imager documents the default as 3 and historically accepts any positive integer.
The line buffer size is computed as image width multiplied by the channel count. Without range enforcement, a negative or very large raw_datachannels value produces an arithmetic result that overflows or requests an unreasonably large allocation. When Imager's allocator fails, it does not raise a Perl exception. It calls exit(3) directly, terminating the host process.
Because exit(3) cannot be trapped by eval { } in Perl, long-running services such as PSGI workers, mod_perl, or job queues die immediately. The impact is denial of service against the entire process, not just the image operation.
Root Cause
Two defects combine. First, raw_datachannels is passed to the reader without a sanity check on sign or upper bound. Second, the buffer size calculation width * channels is not checked for arithmetic overflow before being handed to the allocator. The allocator's failure handler then uses a hard process exit rather than returning an error.
Attack Vector
An attacker supplies a crafted raw image or crafted options to any Perl code path that calls Imager->read() with user-influenced parameters. No authentication is required, and no user interaction is needed beyond submitting the image. Successful exploitation terminates the Perl interpreter.
- RAW:
- validate raw_datachannels and limit to a maximum of 16
- check raw line buffer calculation for overflow
- image creation no longer aborts the process if allocation of the
image surface fails.
Source: GitHub Patch Commit 21b0df9
Detection Methods for CVE-2026-102504
Indicators of Compromise
- Unexpected termination of Perl worker processes handling image uploads, with no Perl die or exception recorded in application logs.
- Web server error logs showing abrupt child process exits during image processing requests.
- CPAN inventories reporting Imager module versions below 1.037.
Detection Strategies
- Inventory Perl dependencies with cpan -l or cpanm --info Imager and flag versions below 1.037.
- Static review of application code for calls to Imager->read() that pass untrusted raw_datachannels, datachannels, xsize, or ysize values.
- Fuzz raw image endpoints with boundary values for raw_datachannels (negative, zero, and values greater than 16) in a controlled environment.
Monitoring Recommendations
- Alert on repeated worker crashes or restart loops in PSGI, FastCGI, or mod_perl servers that process images.
- Capture process exit codes from Perl services and correlate against image upload activity.
- Monitor file upload endpoints for anomalous volume targeting raw image formats.
How to Mitigate CVE-2026-102504
Immediate Actions Required
- Upgrade Imager to version 1.037 or later on all systems running Perl image processing code.
- Audit application code for any path that forwards client-supplied values into Imager->read() and reject non-numeric or out-of-range raw_datachannels input before the call.
- Restart Perl worker processes after upgrading to ensure the patched module is loaded.
Patch Information
The fix is included in Imager 1.037. The patch limits raw_datachannels to a maximum of 16, validates the raw line buffer calculation for overflow, and removes the hard exit from the image allocation failure path. Review the GitHub Security Advisory GHSA-g549-r73g-x7x6 and the MetaCPAN Release Changes for Imager 1.037.
C<raw_datachannels> - the number of channels to read from the file.
Range: 1 to 16. Default: 3. Alternatively and historically spelled
C<datachannels>.
Source: GitHub Patch Commit 21b0df9
Workarounds
- Validate and clamp raw_datachannels to the inclusive range 1 to 16 in application code before invoking Imager.
- Reject raw image formats at the upload layer when raw processing is not required by the application.
- Isolate image processing in short-lived subprocesses so an uncatchable exit does not take down the parent service.
# Upgrade Imager via cpanm to the patched release
cpanm Imager@1.037
# Verify the installed version
perl -MImager -e 'print $Imager::VERSION, "\n"'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.