Bug 2544620 (CVE-2026-102504)

Summary: CVE-2026-102504 perl-Imager: perl-Imager: Denial of Service via out-of-range channel count in raw image reader
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Imager. This vulnerability allows an attacker to cause a Denial of Service (DoS) by supplying an out-of-range channel count parameter when reading raw image files. The application attempts an excessive memory allocation without validating the input, causing an unhandled allocation failure that immediately terminates the process.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2544668    
Bug Blocks:    

Description OSIDB Bzimport 2026-10-01 13:34:27 UTC
Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.

Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3).

Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.