Heap-based Buffer Overflow in GIMP's GIF Export Plug-in
CVE-2026-106064

6.3MEDIUM

What is CVE-2026-106064?

A heap-based buffer overflow vulnerability exists in GIMP’s GIF export plug-in. When an image with exceedingly large dimensions is exported, it can trigger a 32-bit integer overflow, leading to incorrect buffer allocation. Consequently, the plug-in may allocate insufficient memory based on the wrapped value while GEGL operations rely on the actual dimensions of the image. This misalignment can result in severe memory corruption, potentially allowing an attacker to execute arbitrary code during the image export process.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Jim Alves-Foss for reporting this issue.
.