Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read.
The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3).
Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit.
{
"cna_assigner": "CPANSec",
"cwe_ids": [
"CWE-196",
"CWE-789"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93019.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93019.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "119948345469915638569348087927868827618",
"length": 502
},
"id": "CVE-2026-93019-14a1ff64",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/tonycoz/imager/commit/74ed50e0625f9f51054e595bb4a8da92c1e0d571",
"target": {
"file": "tga.c",
"function": "tga_palette_read"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "32324677314543486981969793054927867235",
"length": 4593
},
"id": "CVE-2026-93019-869c7912",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/tonycoz/imager/commit/74ed50e0625f9f51054e595bb4a8da92c1e0d571",
"target": {
"file": "tga.c",
"function": "i_readtga_wiol"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"24946389818946548069221690372982306004",
"182554853386631873384112473511712900606",
"121304537076147117392518683094948683863",
"10697463712083602093601633256085249595",
"169276710584266300954670119928371765706",
"32672159156021958408210554188298091570",
"281505376526195858191462224897644935040",
"214001710070586363545498430646794677202",
"114138852707116573699874210189218068930",
"154806021498833700176078912935005320237",
"231988174533561744030175204268508883925",
"164973520376161982860861450517983646012",
"333008643965020099912947596149461101244",
"290758978354504958713077775810040708511",
"35841989655964752405684908082386329629",
"321431990062157093310062504083217365173",
"242497929311088161972344482418094718546",
"169490625944038890503731656728934781466",
"22065108935528457696630906677665878327",
"114103626073744946411598714635683250717",
"289146296495894907069756397760616148523",
"213669977378289977853669614250714802859",
"235494019502903477543433257223656011799",
"250299292333206135467751777350640812988",
"169604728076340597579856802727417147107",
"323728002856011741762493146324416679361",
"56307087588183969048848314756518608027"
],
"threshold": 0.9
},
"id": "CVE-2026-93019-ecca6ae3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/tonycoz/imager/commit/74ed50e0625f9f51054e595bb4a8da92c1e0d571",
"target": {
"file": "tga.c"
}
}
]
"2026-09-20T14:16:38Z"