Heap Out-of-Bounds Read Vulnerability in GIMP's File-XWD Plugin
CVE-2026-80101

4.4MEDIUM

What is CVE-2026-80101?

A flaw exists in the file-xwd plugin of GIMP where the processing of specially crafted XWD image files results in improper validation of the image width and bytes-per-line parameters. This independent validation leads to discrepancies in their combined values, causing inadequate bounds checking. Consequently, this vulnerability can lead to an application crash and may allow for a denial of service attack or limited information leakage from the heap memory, jeopardizing the integrity of user data.

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Zhixi "Jace" Sun for reporting this issue.
.