Stack Overread Vulnerability in GIMP File-Pix Plugin
CVE-2026-78475
6.1MEDIUM
What is CVE-2026-78475?
A security flaw has been identified in the file-pix plugin of GIMP, where a specially crafted PIX image file prompts the plugin to create a Variable-Length Array (VLA) on the stack improperly, leading to unbounded stack allocation. This mismanagement may result in a 21-byte stack over-read, causing potential denial of service through stack exhaustion and the inadvertent exposure of stack memory contents into an intermediate file. Users of the affected versions should apply available patches to mitigate this issue.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Zhixi "Jace" Sun for reporting this issue.