Heap-based Buffer Overflow in GIMP's GIF Export Plug-in
CVE-2026-106064
6.3MEDIUM
What is CVE-2026-106064?
A heap-based buffer overflow vulnerability exists in GIMP’s GIF export plug-in. When an image with exceedingly large dimensions is exported, it can trigger a 32-bit integer overflow, leading to incorrect buffer allocation. Consequently, the plug-in may allocate insufficient memory based on the wrapped value while GEGL operations rely on the actual dimensions of the image. This misalignment can result in severe memory corruption, potentially allowing an attacker to execute arbitrary code during the image export process.
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jim Alves-Foss for reporting this issue.