PT-2026-55931 · Cpan · Imager

·

CVE-2026-13705

·

Published

2026-07-06

·

Updated

2026-07-08

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Imager versions prior to 1.032
Description An issue exists in the bundled Imager::File::SGI reader where a heap out-of-bounds read occurs during the processing of a 16-bit RLE (Run-Length Encoding) literal run within the read rgb 16 rle() function. The function fails to correctly validate the pixel count against the remaining data length, as it does not account for the fact that each 16-bit sample requires two bytes. Consequently, a specially crafted SGI image processed via Imager->read can trigger an over-read that may crash the process.
Recommendations Update to version 1.032 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13705

Affected Products

Imager