Heap Out-of-Bounds Read in GIMP File-ICO Plugin
CVE-2026-82328
6.1MEDIUM
What is CVE-2026-82328?
A flaw in the file-ico plugin of GIMP allows attackers to exploit improper validation of the palette count parameter in specially crafted ICO image files. This error results in memory bounds not being correctly checked, potentially leading to out-of-bounds reading. An attacker could leverage this vulnerability to cause the application to crash, which may manifest as a denial of service, or to disclose limited contents of the heap memory.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Zhixi "Jace" Sun for reporting this issue.