Heap-Based Out-of-Bounds Write in GIMP Affecting Image Processing Functionality
CVE-2026-6695
5.5MEDIUM
What is CVE-2026-6695?
A vulnerability exists in GIMP, specifically within the PAA file format plugin's decode_lzss() function. This flaw allows a remote attacker to exploit the issue by persuading a user to open a meticulously crafted PAA image file. The attack leads to a heap-based out-of-bounds write, which can result in memory corruption and potentially grant the attacker the ability to execute arbitrary code on the system. This vulnerability necessitates immediate attention to ensure the safety and integrity of users' systems when processing image files.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank JungWooJJING for reporting this issue.