CVE-2026-102505 Overview
CVE-2026-102505 is a heap buffer overflow [CWE-131] in the Imager module for Perl, affecting versions before 1.037. The flaw resides in the i_gsampf_fp routine, which fetches float samples from paletted images. When getsamples() is called with type float, the function allocates a buffer sized for one sample per pixel but writes every requested channel into it. Requesting more than one channel causes writes past the buffer end. An attacker who supplies a crafted image controls the overflowing bytes through the image palette.
Critical Impact
An attacker-controlled image can corrupt heap memory in applications that use Imager to process untrusted paletted images via float sample extraction.
Affected Products
- Tonycoz Imager for Perl, all versions before 1.037
- Applications and web services that process untrusted images using the Imager Perl module
- Downstream Perl distributions bundling vulnerable Imager releases
Discovery Timeline
- 2026-10-01 - CVE-2026-102505 published to the National Vulnerability Database
- 2026-10-01 - Vulnerability discussed on the OpenWall OSS-Security list
- 2026-10-08 - Last updated in NVD database
Technical Details for CVE-2026-102505
Vulnerability Analysis
The vulnerability lives in image.c within the i_gsampf_fp routine. Imager uses this routine to convert 8-bit integer samples to floating-point samples for paletted images. The function allocates a temporary work buffer, fetches samples via i_gsamp, then converts each sample using Sample8ToF before copying into the caller's output buffer.
The allocation only accounts for r-l samples, which is the pixel width of the requested region. However, i_gsamp writes chan_count samples per pixel. When callers request more than one channel, such as RGB or RGBA, writes exceed the allocation by a factor equal to the channel count minus one.
Because the overflowing bytes originate from palette entries, an attacker who controls the input image controls both the overflow size and content. This gives adversaries a reliable primitive to corrupt adjacent heap metadata or application data structures.
Root Cause
The root cause is an incorrect buffer size calculation [CWE-131]. The allocation mymalloc(sizeof(i_sample_t) * (r-l)) omits the chan_count multiplier required to hold every channel of every pixel.
Attack Vector
Exploitation requires an application to process an attacker-supplied paletted image and call getsamples() with type float requesting more than one channel. Image hosting platforms, thumbnail generators, and Perl-based web services that accept user uploads are the primary exposure surface.
// Security patch in image.c - fix memory allocation for i_gsampf_fp
if (r > l) {
i_img_dim ret;
i_img_dim i;
- work = mymalloc(sizeof(i_sample_t) * (r-l));
+ work = mymalloc(sizeof(i_sample_t) * (r-l) * chan_count);
ret = i_gsamp(im, l, r, y, work, chans, chan_count);
for (i = 0; i < ret; ++i) {
samp[i] = Sample8ToF(work[i]);
Source: GitHub Patch for Imager. The patch multiplies the allocation by chan_count, correctly sizing the work buffer for multi-channel fetches.
Detection Methods for CVE-2026-102505
Indicators of Compromise
- Unexpected crashes or segmentation faults in Perl processes that invoke Imager on uploaded images
- Heap corruption signatures reported by glibc such as malloc(): memory corruption or free(): invalid pointer
- Anomalous paletted image uploads with unusual palette sizes or crafted channel configurations
Detection Strategies
- Inventory installed Imager versions across Perl environments and flag any release below 1.037
- Audit application code for calls to getsamples() or i_gsampf_fp that pass more than one channel on paletted images
- Run fuzz testing with malformed paletted images against image-processing endpoints to surface crashes before adversaries do
Monitoring Recommendations
- Monitor image-processing worker processes for abnormal exits, core dumps, and ASan or Valgrind reports
- Log and review upload patterns for repeated submissions of paletted images from the same source
- Alert on image-processing service restarts or watchdog recoveries that correlate with user upload activity
How to Mitigate CVE-2026-102505
Immediate Actions Required
- Upgrade Imager to version 1.037 or later across every Perl environment
- Restrict image uploads to trusted users while patches are being deployed
- Rebuild and redeploy container images and CI artifacts that bundle the vulnerable Imager version
Patch Information
The upstream fix is available in the commit referenced by the GitHub Patch for Imager and shipped in Imager 1.037. Release details are documented in the MetaCPAN Change Log for Imager and the GitHub Security Advisory GHSA-4rx6. Discussion is available on the OpenWall OSS-Security Discussion thread.
Workarounds
- Avoid calling getsamples() with type float on paletted images until the upgrade is applied
- Convert paletted images to a non-paletted format before sampling, when possible
- Validate and reject input images with unexpected palette structures at the application boundary
# Upgrade Imager via cpanm to the fixed release
cpanm Imager@1.037
# Verify the installed version
perl -MImager -e 'print $Imager::VERSION, "\n"'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.