CVE-2026-8669

EUVD-2026-30541
Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files.

Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file.

The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such check.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CPANSecCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
tonycimager\
𝑥
≤ 1.30
CNA
Debian logo
Debian Releases
Debian Product
Codename
libimager-perl
bookworm
no-dsa
bullseye
no-dsa
forky
1.031+dfsg-1
fixed
sid
1.031+dfsg-1
fixed
trixie
no-dsa