Heap Buffer Over-read Vulnerability in GIMP PCX File Loader
CVE-2026-4887
6.1MEDIUM
What is CVE-2026-4887?
A critical vulnerability in GIMP's PCX file loader has been identified, resulting from an off-by-one error that leads to heap buffer over-read issues. This flaw allows a remote attacker to craft a malicious PCX image, which, when opened by an unsuspecting user, could trigger out-of-bounds memory access. The result can be significant, leading to memory disclosure and potentially crashing the application, thereby causing a Denial of Service (DoS). Users are urged to remain vigilant and apply updates to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Meshaal for reporting this issue.