Bug 2544621 (CVE-2026-102505)

Summary: CVE-2026-102505 perl-Imager: perl-Imager: Arbitrary code execution via heap-based buffer overflow in paletted image processing
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in perl-Imager. When processing floating-point samples from a paletted image, the application allocates an undersized buffer for multi-channel requests. An attacker could provide a specially crafted image to trigger a heap-based buffer overflow with controlled data, potentially leading to arbitrary code execution or a Denial of Service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2544669    
Bug Blocks:    

Description OSIDB Bzimport 2026-10-01 13:34:48 UTC
Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.

For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end.

An attacker-supplied image controls the overflowing bytes through its palette.