Heap-Based Buffer Overflow in GIMP File-Fits Plugin
CVE-2026-66758
7.8HIGH
What is CVE-2026-66758?
A vulnerability exists in the file-fits plugin of GIMP where an integer overflow can occur during the processing of a FITS image file. This occurs when extremely large width and height values are provided, leading to an incorrect allocation size for the buffer. When the cfitsio component attempts to write data, it can trigger a buffer overflow, which may corrupt memory. This condition could allow an attacker to execute arbitrary code or cause a denial of service on an affected system.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Tristan Madani for reporting this issue.