← Back to search

CVE-2026-93019

9.1 CRITICALpublic exploit available

Published 2026-09-18 · Updated 2026-09-18

AI risk analysis

Summary
The flaw allows an attacker to cause the Imager Perl module to exit unexpectedly by providing a TGA file with a colour map length of 32768 or more, leading to a denial of service.
Exploitability
Exploitation is relatively straightforward as it requires only crafting a specific TGA file and reading it through Imager's API. The attacker must have the ability to supply the file to the application.
Blast radius
If exploited, the impact is limited to the application crashing, potentially leading to a denial of service for the service relying on Imager.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Imager version 1.036 or later.
dosperlimage-processing

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3). Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Weaknesses

CWE-196, CWE-789

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.