Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.
Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3).
Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.
{
"cna_assigner": "CPANSec",
"cwe_ids": [
"CWE-190",
"CWE-789"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102504.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "1.037"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"fixed": "1.037"
}
],
"source": "DESCRIPTION"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102504.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "207357776269421899668439933285550746615",
"length": 1798
},
"id": "CVE-2026-102504-a97d4103",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/tonycoz/imager/commit/21b0df9eef1dffe1fdcd3706bfea9f1338031679",
"target": {
"file": "raw.c",
"function": "i_readraw_wiol"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"328463924939409605534426249642733758021",
"168051128911534474624230533184760800684",
"209000987498789475117558425190550600752",
"282926231535019204558933664452818662303",
"284683587321965164414290235504640101272",
"266974199856811874455701382100747166544",
"294332306576663194491368921611203116168",
"262659248325399998910084395603953965701",
"163830203813207452959878439816998971040"
],
"threshold": 0.9
},
"id": "CVE-2026-102504-eed4a9e3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/tonycoz/imager/commit/21b0df9eef1dffe1fdcd3706bfea9f1338031679",
"target": {
"file": "raw.c"
}
}
]
"2026-10-03T08:04:04Z"