Heap-Based Out-of-Bounds Write in GIMP Affecting Image Processing Functionality
CVE-2026-6695

5.5MEDIUM

What is CVE-2026-6695?

A vulnerability exists in GIMP, specifically within the PAA file format plugin's decode_lzss() function. This flaw allows a remote attacker to exploit the issue by persuading a user to open a meticulously crafted PAA image file. The attack leads to a heap-based out-of-bounds write, which can result in memory corruption and potentially grant the attacker the ability to execute arbitrary code on the system. This vulnerability necessitates immediate attention to ensure the safety and integrity of users' systems when processing image files.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank JungWooJJING for reporting this issue.
.