Signed Integer Overflow Vulnerability in GIMP's file-fli Plugin
CVE-2026-59088

5.5MEDIUM

What is CVE-2026-59088?

A vulnerability has been identified in GIMP specifically within the file-fli plugin, which processes FLI image files. This flaw is due to an improper calculation that occurs during memory allocation for image buffers. When the plugin attempts to multiply the image's width and height, the resulting value can exceed the maximum integer limit, leading to a signed integer overflow. An attacker could exploit this flaw by persuading users into opening specially crafted FLI files. Successful exploitation may cause the GIMP application to crash, resulting in a denial of service for the user. It is crucial for users to be aware of this vulnerability and update to mitigate risks.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.