#1141959 libimager-perl: CVE-2026-14454

Package:
src:libimager-perl
Source:
src:libimager-perl
Submitter:
Salvatore Bonaccorso
Date:
2026-07-12 20:53:02 UTC
Severity:
normal
Tags:
#1141959#5
Date:
2026-07-12 20:11:52 UTC
From:
To:
Hi,

The following vulnerability was published for libimager-perl.

CVE-2026-14454[0]:
| Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry
| counts as signed.  Imager mishandled large EXIF IFD entry count
| values, treating them as negative numbers.  This could lead to an
| attempt to allocate a block nearly the size of the address space,
| which fails and kills the process.  An attacker could craft an image
| with EXIF data that terminates a worker process.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-14454
https://www.cve.org/CVERecord?id=CVE-2026-14454
[1] https://lists.security.metacpan.org/cve-announce/msg/41637674/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1141959#10
Date:
2026-07-12 20:50:35 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libimager-perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141959@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
gregor herrmann <gregoa@debian.org> (supplier of updated libimager-perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 12 Jul 2026 22:24:23 +0200
Source: libimager-perl
Architecture: source
Version: 1.033+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: gregor herrmann <gregoa@debian.org>
Closes: 1141959
Changes:
 libimager-perl (1.033+dfsg-1) unstable; urgency=medium
 .
   * Import upstream version 1.033+dfsg.
     - fix mishandling of large EXIF IFD entry count values, treating them as
       negative numbers.
       CVE-2026-14454
     Closes: #1141959
Checksums-Sha1:
 3a757c58631ce83c48bc56986a9f082e9fbe6a60 2659 libimager-perl_1.033+dfsg-1.dsc
 f3a7945bd8ac5246172b7fbdbf37fb14aa970ee8 935996 libimager-perl_1.033+dfsg.orig.tar.xz
 36327111f89cdbc025c48d9f80869467052626e2 13412 libimager-perl_1.033+dfsg-1.debian.tar.xz
Checksums-Sha256:
 424ffa75715506ca67c3be5974475f22f61827c97b68a2503d0020e5919de7ac 2659 libimager-perl_1.033+dfsg-1.dsc
 9d52c3041dfabe29209bdd78b3c243c894e4acb89c6555d3a6915c5b805ade7d 935996 libimager-perl_1.033+dfsg.orig.tar.xz
 3deff29910f396cb8025a85682e0f5d6806ffa45a40f19523cb751bae42f7583 13412 libimager-perl_1.033+dfsg-1.debian.tar.xz
Files:
 7918134c7a05117a801a697b02402366 2659 perl optional libimager-perl_1.033+dfsg-1.dsc
 6fd5c96eba36d758752ac9b5c8aff144 935996 perl optional libimager-perl_1.033+dfsg.orig.tar.xz
 e5521d806a374203681f2b696631e8eb 13412 perl optional libimager-perl_1.033+dfsg-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmpT+NBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgZo4Q/8Ca3QOIic5Q0XmU20y5RidPs3qMYMizzAsSlAySH8f4JEWASs1wgEZNp2
JKUyMkWmMyfezuSNm7BwYUpsWNMlPJrIK5df1SfOVVSn1Y+lEcJG2EdnPBEIiJ9S
Fl6DREOlUm8f4yPBzbKzmsztTsOZUrEm99ws8xllaCUN2P9tDDHN7jEnVrRULpkE
qNFOpiHdptfayOKnfsMcq2TZFIqcjl9gTcKZnUftnRUOdfVjyQm0hYU6xi5jQanV
4T5o4AP7p4WU81mBFvMl1lZ/DhzeBWILUG0nYso9NRYKFQqPPtG1g7hxeDxBJbOX
TR1tlHdjwiFPbrcfhUztF5mEXIfKYF68f5cdbyiQ2qgApo+vXwfskfC5o72+FJa3
e1NBcZLt8hlKK9sd+18752guJ5PhjhAaBSHGahP7bYuBleCCnw/rIRiEfiRKzema
tMnXtO34YnP1TlZrdrg8i1Sd4IaD2b0C0WFR/xXBCPk4Xrdm13Sj8i3QA8nwWaRs
xVY9xUk6R4nv5tSPduQHbuDZoTA90fMGxm338IPFAXvzi3FBqjbgF+BEsB8eXZdZ
qMXiFrN3chNn5q11gEPIl5PizzIEzNMK1ZU500jMk4Ua15wTPWWFeOjbk3IbSK8k
tX0P1S88I5j0uVvcjaKStyupfYE1VrQqPxT4cYGutm7yW96nnFM=
=HPj0
-----END PGP SIGNATURE-----