Heap-Based Buffer Overflow in GIMP's Raw Data Export Plug-In
CVE-2026-106066
6.3MEDIUM
What is CVE-2026-106066?
A heap-based buffer overflow has been identified in GIMP's raw data export plug-in. This vulnerability occurs when exporting very large images, as the memory allocation through g_malloc() uses an incorrectly calculated size based on width, height, and bytes-per-pixel. An integer overflow can lead to insufficient memory being allocated compared to the amount required during export operations, creating a potential risk during image processing tasks.
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jim Alves-Foss for reporting this issue.