Heap Overflow Vulnerability in GIMP File-PVR Plugin
CVE-2026-82330
6.1MEDIUM
What is CVE-2026-82330?
A vulnerability in the file-pvr plugin for GIMP exposes the application to potential exploitation due to improper memory bounds checking when processing specially crafted PVR image files. This oversight can lead to heap out-of-bounds reads, resulting in application crashes and possible disclosure of sensitive heap memory contents. Users are advised to update to patched versions to protect against these risks.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Zhixi "Jace" Sun for reporting this issue.