{"id":"CVE-2026-102505","summary":"Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp","details":"Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.\n\nFor a paletted image, getsamples() with type \"float\" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes past its end.\n\nAn attacker-supplied image controls the overflowing bytes through its palette.","aliases":["GHSA-4rx6-cgv3-fmxp"],"modified":"2026-10-03T08:04:05.126610Z","published":"2026-10-01T13:11:51.967Z","database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-131"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102505.json","unresolved_ranges":[{"extracted_events":[{"fixed":"1.037"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"1.037"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/10/01/10"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102505.json"},{"type":"ADVISORY","url":"https://github.com/tonycoz/imager/security/advisories/GHSA-4rx6-cgv3-fmxp"},{"type":"ADVISORY","url":"https://metacpan.org/release/TONYC/Imager-1.037/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102505"},{"type":"FIX","url":"https://github.com/tonycoz/imager/commit/aae49c6be065aa467e834105c816359394a634db.patch"},{"type":"PACKAGE","url":"https://github.com/tonycoz/imager"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tonycoz/imager","events":[{"introduced":"0"},{"fixed":"aae49c6be065aa467e834105c816359394a634db"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v1.036","v1.035","v1.034","v1.033","v1.032","v1.031","v1.030","v1.029","v1.028","v1.027","v1.026","v1.025","v1.024","v1.023","v1.022","v1.021","v1.020","v1.019","v1.018","v1.017","v1.016","v1.015","v1.014","v1.013","v1.012","v1.011","v1.010","v1.009","v1.008","v1.007","v1.006","v1.005","v1.004_004","v1.004_003","v1.004_002","v1.004_001","v1.004","v1.003","v1.002","v1.001","v1.000","v0.99_02","v0.99_01","v0.99","v0.98","v0.97","v0.96_02","v0.96_01","v0.96","v0.95","v0.94_02","v0.94_01","v0.94","v0.93","v0.92","v0.91","v0.90","v0.89","v0.88","v0.87","v0.86","v0.85_02","v0.85_01","v0.85","v0.84_02","v0.84_01","v0.84","v0.83","v0.82_01","Imager-0.82","Imager-0.81","Imager-0.80","Imager-0.79","Imager-0.78","Imager-0.77","Imager-0.76","Imager-0.75","Imager-0.72","Imager-0.71","Imager-0.65","Imager-0.63","Imager-0.61","Imager-0.60","Imager-0.59","Imager-0.58","Imager-0.55","Imager-0.53","Imager-0.52","Imager-0.51_02","Imager-0.51_01","Imager-0.49","Imager-0_38pre9","Imager-0_38"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102505.json","vanir_signatures_modified":"2026-10-03T08:04:05Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"79426211150758305460935633913640526500","length":623},"id":"CVE-2026-102505-aed3dd76","signature_type":"Function","signature_version":"v1","source":"https://github.com/tonycoz/imager/commit/aae49c6be065aa467e834105c816359394a634db","target":{"file":"image.c","function":"i_gsampf_fp"}},{"target":{"file":"image.c"},"deprecated":false,"digest":{"line_hashes":["48036270986658032629210103816564198979","160253456048622132399737474495174592220","180234216527550753567666581429859310167","319531769243159788572291725409526686459"],"threshold":0.9},"id":"CVE-2026-102505-ef5b5871","signature_type":"Line","signature_version":"v1","source":"https://github.com/tonycoz/imager/commit/aae49c6be065aa467e834105c816359394a634db"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}