Heap Buffer Overflow in GIMP's APNG File Loader and DDS Plug-in
CVE-2026-42169

7.3HIGH

What is CVE-2026-42169?

A heap buffer overflow vulnerability exists in GIMP's Animated PNG (APNG) file loader which can be exploited when the 'fcTL' width surpasses the 'IHDR' width. This flaw allows for pixel data being written beyond the allocated heap space. Additionally, a separate heap buffer overflow issue is present in the DDS plug-in, stemming from a bits-per-pixel (BPP) mismatch in the 'load_layer()' function. Both vulnerabilities are triggered by opening a specially crafted image file, posing a risk of code execution by malicious actors.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Rakan Alotaibi (@hxteam) for reporting this issue.
.