Heap-Based Buffer Overflow in Dia Diagram Editor's WPG File Importer
CVE-2026-77652

7.8HIGH

Key Information:

Vendor

Gnome

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-77652?

A heap-based buffer overflow vulnerability exists in the Dia diagram editor's WPG file format importer. This issue arises when the WPG import renderer processes color palettes for WPG_COLORMAP records, with insufficient validation of the indices used to read palette data. Maliciously crafted WPG files can exploit this vulnerability, potentially allowing for arbitrary code execution or crashing the Dia application due to memory corruption. Users are at risk of exploitation if they are misled into opening a malicious WPG file, which does not require elevated permissions.

Affected Version(s)

Dia 0 <= 0.98+git20260221-1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Robin "drzobin" Larsson for reporting this issue.
.