Medium severity5.3NVD Advisory· Published May 15, 2026· Updated May 15, 2026
CVE-2026-8454
CVE-2026-8454
Description
Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files.
Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file.
The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such check.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
1- UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW MalwareThe Hacker News · Apr 23, 2026