Advisories ยป MGASA-2026-0284

Updated perl-Imager package fixes security vulnerabilities

Publication date: 20 Jul 2026
Modification date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2024-53901 , CVE-2026-13705 , CVE-2026-13708 , CVE-2026-14454

Description

The updated package fixes security vulnerabilities:
The Imager package before 1.025 for Perl has a heap-based buffer
overflow leading to denial of service, or possibly unspecified other
impact, when the trim() method is called on a crafted input image.
(CVE-2024-53901)
Imager versions before 1.032 for Perl have a heap out-of-bounds read in
the bundled Imager::File::SGI reader via a 16-bit RLE literal run in
read_rgb_16_rle. (CVE-2026-13705)
Imager::File::JPEG versions before 1.003 for Perl leak heap memory when
reading a JPEG with repeated APP13 markers in i_readjpeg_wiol.
(CVE-2026-13708)
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry
counts as signed. (CVE-2026-14454)
                

References

SRPMS

10/core

9/core