Buffer Overflow Vulnerability in GIMP's XMC Thumbnail Loader
CVE-2026-106061
5.5MEDIUM
What is CVE-2026-106061?
A flaw in GIMP's X cursor (XMC) thumbnail loader can lead to a buffer overflow due to improper handling of pixel buffer allocation. When processing a malicious XMC file, GIMP computes the buffer size with 32-bit signed arithmetic, which may overflow. This causes the allocation to be smaller than necessary. Consequently, a later read operation using these incorrect dimensions can result in out-of-bounds memory access, potentially crashing the application and corrupting memory. It highlights a significant risk within the image processing pipeline, emphasizing the importance of secure coding practices.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jim Alves-Foss for reporting this issue.