
Perl CPAN CVE-2026-14454: Imager before 1.033 treat unsigned EXIF IFD entry counts as signed https://www.openwall.com/lists/oss-security/2026/07/08/6 attempt to allocate a block nearly the size of the address space, which fails and kills the process. Crafted image with EXIF data could terminate a worker process.
Post summary
The snippet discusses CVE‑2026‑14454, noting how unsigned EXIF IFD counts are misinterpreted and can cause a crash via a large memory allocation, but it provides no PoC, exploit code, patch, or evidence of active exploitation.

