Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-93019: Imager Perl library can crash when opening crafted TGA image
CVE-2026-93019 · published 10 days ago
Summary
The Imager library used on Debian and Ubuntu systems may stop the program when it reads a specially made TGA picture that reports a very large colour map. This happens because the library miscalculates the size needed and forces the program to exit. Avoid the issue by updating Imager to version 1.036 or later, or by not processing untrusted TGA files.
What to do
- Update debian libimager-perl to version 1.036+dfsg-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:14 | debian | libimager-perl |
< 1.036+dfsg-1 Fix: upgrade to 1.036+dfsg-1
|
| Debian:12 | debian | libimager-perl | All versions |
| Ubuntu:16.04:LTS | canonical | libimager-perl | All versions |
Original advisory text
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3). Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit.
References
- https://github.com/tonycoz/imager/commit/74ed50e0625f9f51054e595bb4a8da92c1e0d57... Patch
- https://github.com/tonycoz/imager/security/advisories/GHSA-p4vw-rc54-p2c2 Vendor Advisory
- https://metacpan.org/release/TONYC/Imager-1.036/changes Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-93019 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/09/18/9 URL
- https://cpan.org/modules URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93019... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-93019 Vendor Advisory
- https://github.com/tonycoz/imager Product
- https://ubuntu.com/security/CVE-2026-93019 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-93019 Third Party Advisory
- https://lists.security.metacpan.org/cve-announce/msg/43654761/ Third Party Advisory
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-196Unsigned to Signed Conversion Error
CWE-789Memory Allocation with Excessive Size Value
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Sources
CVE-2026-93019 · NVD
CVE-2026-93019 · MITRE
DEBIAN-CVE-2026-93019 · OSV
CVE-2026-93019 · OSV
GHSA-p4vw-rc54-p2c2 · GHSA
UBUNTU-CVE-2026-93019 · OSV
Track software like this
Free during beta