Heap-Based Buffer Overflow in GIMP's Raw Data Export Plug-In
CVE-2026-106066

6.3MEDIUM

What is CVE-2026-106066?

A heap-based buffer overflow has been identified in GIMP's raw data export plug-in. This vulnerability occurs when exporting very large images, as the memory allocation through g_malloc() uses an incorrectly calculated size based on width, height, and bytes-per-pixel. An integer overflow can lead to insufficient memory being allocated compared to the amount required during export operations, creating a potential risk during image processing tasks.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Jim Alves-Foss for reporting this issue.
.