Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-93019: Imager Perl library can crash when opening crafted TGA image

CVE-2026-93019 · published 10 days ago
Summary

The Imager library used on Debian and Ubuntu systems may stop the program when it reads a specially made TGA picture that reports a very large colour map. This happens because the library miscalculates the size needed and forces the program to exit. Avoid the issue by updating Imager to version 1.036 or later, or by not processing untrusted TGA files.

What to do
  • Update debian libimager-perl to version 1.036+dfsg-1.
Affected software
Ecosystem VendorProductAffected versions
Debian:14 debian libimager-perl < 1.036+dfsg-1
Fix: upgrade to 1.036+dfsg-1
Debian:12 debian libimager-perl All versions
Ubuntu:16.04:LTS canonical libimager-perl All versions
Original advisory text
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3). Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-196Unsigned to Signed Conversion Error
CWE-789Memory Allocation with Excessive Size Value
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Track software like this
Free during beta