Buffer Overflow Vulnerability in GIMP's XMC Thumbnail Loader
CVE-2026-106061

5.5MEDIUM

What is CVE-2026-106061?

A flaw in GIMP's X cursor (XMC) thumbnail loader can lead to a buffer overflow due to improper handling of pixel buffer allocation. When processing a malicious XMC file, GIMP computes the buffer size with 32-bit signed arithmetic, which may overflow. This causes the allocation to be smaller than necessary. Consequently, a later read operation using these incorrect dimensions can result in out-of-bounds memory access, potentially crashing the application and corrupting memory. It highlights a significant risk within the image processing pipeline, emphasizing the importance of secure coding practices.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Jim Alves-Foss for reporting this issue.
.