{"id":"CVE-2026-93019","summary":"Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read","details":"Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read.\n\nThe reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3).\n\nReading an attacker-supplied file through Imager-\u003eread() triggers an uncatchable exit.","aliases":["GHSA-p4vw-rc54-p2c2"],"modified":"2026-09-19T03:46:47.006059114Z","published":"2026-09-18T13:58:12.083Z","database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-196","CWE-789"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93019.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/09/18/9"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93019.json"},{"type":"PACKAGE","url":"https://github.com/tonycoz/imager"},{"type":"FIX","url":"https://github.com/tonycoz/imager/commit/74ed50e0625f9f51054e595bb4a8da92c1e0d571.patch"},{"type":"ADVISORY","url":"https://github.com/tonycoz/imager/security/advisories/GHSA-p4vw-rc54-p2c2"},{"type":"ADVISORY","url":"https://metacpan.org/release/TONYC/Imager-1.036/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93019"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tonycoz/imager","events":[{"introduced":"0"},{"fixed":"0998bfbf88c1deeb080b9b07ec9ed9df6db5b363"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.036"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.035","v1.034","v1.033","v1.032","v1.031","v1.030","v1.029","v1.028","v1.027","v1.026","v1.025","v1.024","v1.023","v1.022","v1.021","v1.020","v1.019","v1.018","v1.017","v1.016","v1.015","v1.014","v1.013","v1.012","v1.011","v1.010","v1.009","v1.008","v1.007","v1.006","v1.005","v1.004_004","v1.004_003","v1.004_002","v1.004_001","v1.004","v1.003","v1.002","v1.001","v1.000","v0.99_02","v0.99_01","v0.99","v0.98","v0.97","v0.96_02","v0.96_01","v0.96","v0.95","v0.94_02","v0.94_01","v0.94","v0.93","v0.92","v0.91","v0.90","v0.89","v0.88","v0.87","v0.86","v0.85_02","v0.85_01","v0.85","v0.84_02","v0.84_01","v0.84","v0.83","v0.82_01","Imager-0.82","Imager-0.81","Imager-0.80","Imager-0.79","Imager-0.78","Imager-0.77","Imager-0.76","Imager-0.75","Imager-0.72","Imager-0.71","Imager-0.65","Imager-0.63","Imager-0.61","Imager-0.60","Imager-0.59","Imager-0.58","Imager-0.55","Imager-0.53","Imager-0.52","Imager-0.51_02","Imager-0.51_01","Imager-0.49","Imager-0_38pre9","Imager-0_38"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93019.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}