Heap Buffer Overflow in GIMP's APNG File Loader and DDS Plug-in
CVE-2026-42169
7.3HIGH
What is CVE-2026-42169?
A heap buffer overflow vulnerability exists in GIMP's Animated PNG (APNG) file loader which can be exploited when the 'fcTL' width surpasses the 'IHDR' width. This flaw allows for pixel data being written beyond the allocated heap space. Additionally, a separate heap buffer overflow issue is present in the DDS plug-in, stemming from a bits-per-pixel (BPP) mismatch in the 'load_layer()' function. Both vulnerabilities are triggered by opening a specially crafted image file, posing a risk of code execution by malicious actors.
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Rakan Alotaibi (@hxteam) for reporting this issue.