CVE-2026-73639: Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8
Perl module Imager::File::PNG before 1.004 writes past the end of the row buffer when reading PNGs with a tRNS transparency chunk.
CVE-2026-73639 affects Imager::File::PNG versions 1.003 through before 1.004 for Perl. The flaw is a write past the end of the row buffer in read_direct8 when processing a PNG containing a tRNS transparency chunk. The bug was disclosed on the oss-security mailing list by Stig Palmquist, with the fix available in version 1.004.
40