CPANSA-Imager-2026-14454: Imager vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-07-08T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-07-08T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 9.8 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.
Vulnerabilities
CVE-2026-14454
Vulnerability DescriptionImager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed.
Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process.
An attacker could craft an image with EXIF data that terminates a worker process.
| Weakness | CWE-196 : Unsigned to Signed Conversion Error |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Imager less than 1.033 |
|
Fixed
- Imager greater than or equal 1.033
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Imager-2026-14454 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-imager-2026-14454.json - https://github.com/tonycoz/imager/commit/06f01a5d0fd591259aeba589370d6888384a6b6d.patch external
https://github.com/tonycoz/imager/commit/06f01a5d0fd591259aeba589370d6888384a6b6d.patch - https://metacpan.org/release/TONYC/Imager-1.033/changes external
https://metacpan.org/release/TONYC/Imager-1.033/changes - http://www.openwall.com/lists/oss-security/2026/07/08/6 external
http://www.openwall.com/lists/oss-security/2026/07/08/6 - CVE-2026-14454 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-14454
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Wed Jul 8 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/