Heap-based Buffer Overflow in GIMP’s DICOM Export Plug-in
CVE-2026-106063

6.3MEDIUM

What is CVE-2026-106063?

A heap-based buffer overflow vulnerability exists in GIMP's DICOM export plug-in. When an image with extraordinarily large dimensions is exported, a buffer is allocated based on the 32-bit product of width, height, and bytes-per-pixel. This can lead to an overflow as GEGL writes the complete uncompressed data into a buffer that is insufficiently sized due to an integer overflow during the allocation process.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Jim Alves-Foss for reporting this issue.
.