Heap Out-of-Bounds Read Vulnerability in GIMP's File-XWD Plugin
CVE-2026-80101
4.4MEDIUM
What is CVE-2026-80101?
A flaw exists in the file-xwd plugin of GIMP where the processing of specially crafted XWD image files results in improper validation of the image width and bytes-per-line parameters. This independent validation leads to discrepancies in their combined values, causing inadequate bounds checking. Consequently, this vulnerability can lead to an application crash and may allow for a denial of service attack or limited information leakage from the heap memory, jeopardizing the integrity of user data.
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Zhixi "Jace" Sun for reporting this issue.