Heap-Based Buffer Overflow in GIMP's PCX Export Plu-in
CVE-2026-106065
6.3MEDIUM
What is CVE-2026-106065?
A heap-based buffer overflow has been identified in GIMP’s PCX export plug-in. This vulnerability arises when handling images that exceed specific dimensions. During buffer allocation, the calculations for width and height use a 32-bit integer, which can lead to an overflow condition. As a result, the memory allocation may not be sufficient, leading to potential exploitation during GEGL operations that utilize the improperly calculated sizes. This can compromise the integrity and confidentiality of the system, making it crucial for users to stay informed and apply any relevant updates.
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jim Alves-Foss for reporting this issue.