Impact
A heap‐based buffer overflow was discovered in GIMP’s DICOM export plug‑in. When an image with extremely large dimensions is exported, the plug‑in calculates the allocation size using a 32‑bit product of width, height and bytes‑per‑pixel. If this product overflows, the allocated buffer is smaller than required and GEGL writes the uncompressed image data into the undersized buffer, leading to memory corruption. The vulnerability could allow an attacker to trigger arbitrary code execution or a denial‑of‑service condition, depending on the context in which GIMP is used.
Affected Systems
The flaw affects GIMP installations bundled with Red Hat Enterprise Linux 6 through 10, including Red Hat Enterprise Linux 6, 7, 8, 9 and 10. Any system running these distributions and allowing image export to DICOM is vulnerable.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack is likely to require access to a process that performs a DICOM export, such as a local application or a service that accepts user‑supplied images. Because the CVE description does not provide evidence of remote exploitation, the risk is inferred to be lower for pure network‑based attacks but remains significant for local or privileged users.
OpenCVE Enrichment