« Volver al listado

CVE-2026-73639

Estado: AplazadaCrítica (9.1)—

Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8.

With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the original channel count. libpng expands the transparency into that extra channel, so png_read_row() fills one channel more than the buffer holds, at one byte per sample, and writes width bytes past the end of the allocation. Palette images go to read_paletted() and 16-bit images to read_direct16(), which sizes its buffer from png_get_rowbytes() and allocates enough for the expanded row.

Leer descripción completaMostrar menos

The same reader ships bundled in the Imager distribution.

Reading an attacker-supplied PNG through Imager->read() corrupts the heap, which can crash the process.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Buffer overflow (CWE-787) en PNG parser accesible remotamente (AV:N, PR:N, UI:N) causa corrupción de heap y DoS de aplicación. No se demuestra RCE.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-73639",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-73639",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-22T18:04:27.077498Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "affectedData": [
        {
          "repo": "https://github.com/tonycoz/imager",
          "modules": [
            "Imager::File::PNG"
          ],
          "versions": [
            {
              "status": "affected",
              "version": "1.003",
              "lessThan": "1.004",
              "versionType": "custom"
            }
          ],
          "packageURL": "pkg:cpan/Imager-File-PNG",
          "packageName": "Imager-File-PNG",
          "programFiles": [
            "impng.c"
          ],
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "read_direct8"
            }
          ]
        },
        {
          "repo": "https://github.com/tonycoz/imager",
          "modules": [
            "Imager::File::PNG"
          ],
          "versions": [
            {
              "status": "affected",
              "version": "1.034",
              "lessThan": "1.035",
              "versionType": "custom"
            }
          ],
          "packageURL": "pkg:cpan/Imager",
          "packageName": "Imager",
          "programFiles": [
            "PNG/impng.c"
          ],
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "read_direct8"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-17T22:17:03.763",
  "references": [
    {
      "url": "https://github.com/tonycoz/imager/commit/d973bd7e8843f084e8071caa24b89545c88b1e4b.patch",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://github.com/tonycoz/imager/pull/567",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://github.com/tonycoz/imager/security/advisories/GHSA-jhx5-34j8-9g88",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/TONYC/Imager-1.035/changes",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/TONYC/Imager-File-PNG-1.004/changes",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/09/17/6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8.\n\nWith a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the original channel count. libpng expands the transparency into that extra channel, so png_read_row() fills one channel more than the buffer holds, at one byte per sample, and writes width bytes past the end of the allocation. Palette images go to read_paletted() and 16-bit images to read_direct16(), which sizes its buffer from png_get_rowbytes() and allocates enough for the expanded row.\n\nThe same reader ships bundled in the Imager distribution.\n\nReading an attacker-supplied PNG through Imager->read() corrupts the heap, which can crash the process."
    }
  ],
  "lastModified": "2026-09-22T19:16:44.383",
  "sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}