Heap-based Buffer Overflow in GIMP's Hot Color Filter Plugin
CVE-2026-106067

6.3MEDIUM

What is CVE-2026-106067?

A heap-based buffer overflow vulnerability has been identified in GIMP's Hot color filter plugin. This issue occurs when allocating a pixel buffer for large images. The flawed arithmetic in calculating buffer dimensions can lead to an integer overflow, enabling a mismatch between the allocated pixel buffer size and the actual image size. This can result in unexpected behavior, including potential crashes or the execution of arbitrary code, thereby compromising the integrity of image processing operations.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Jim Alves-Foss for reporting this issue.
.