CVE-2026-8669Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such check.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-20); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-20: 1Mentions · 2026-05-29: 1Patch / Workaround · 2026-05-29: 1Technical Details · 2026-05-20: 105-2005-29
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-201
Disclosure1
2026-05-291
Patch1
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-8454: Imager::File::GIF through 1.002 allow a heap out of bounds write on crafted multi-frame GIF files https://www.openwall.com/lists/oss-security/2026/05/15/15 CVE-2026-8669: Imager through 1.030 allow a heap out of bounds write on crafted multi-frame GIF files https://www.openwall.com/lists/oss-security/2026/05/15/17

    Post summary

    The notice announces two heap‑out‑of‑bounds write vulnerabilities (CVE‑2026‑8454 and CVE‑2026‑8669) affecting Perl’s Imager library when handling crafted multi‑frame GIF files, with links to detailed discussions in the OpenWall mailing list.

    11051834
    4.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🐧 Se você usa #Mageia e processa imagens GIF em Perl, precisa ler isso. Vulnerabilidade grave no módulo Imager (CVE-2026-8669) foi corrigida, mas será que você já aplicou o patch? Saiba mais -> http://tinyurl.com/y7yhbc9h https://t.co/UADfX09NHO

    Post summary

    The tweet alerts Mageia users who process GIFs in Perl about a serious vulnerability (CVE-2026-8669) in the Imager module, noting that it has been patched and encouraging application of the fix.

    1000075
    1.5K followersView on X

Explore more