Heap Buffer Over-read Vulnerability in GIMP PCX File Loader
CVE-2026-4887

6.1MEDIUM

What is CVE-2026-4887?

A critical vulnerability in GIMP's PCX file loader has been identified, resulting from an off-by-one error that leads to heap buffer over-read issues. This flaw allows a remote attacker to craft a malicious PCX image, which, when opened by an unsuspecting user, could trigger out-of-bounds memory access. The result can be significant, leading to memory disclosure and potentially crashing the application, thereby causing a Denial of Service (DoS). Users are urged to remain vigilant and apply updates to mitigate this risk.

Affected Version(s)

Red Hat Enterprise Linux 8 8100020260512115927.4c9c024f

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 8040020260520140422.70584597

Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 8040020260520140422.70584597

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Meshaal for reporting this issue.
.