Description
A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export path allocates a buffer using a 32-bit width * height (and bytes-per-pixel) product that can overflow. GEGL then writes the full uncompressed extent into the undersized buffer (CWE-787), after integer overflow in the allocation size
Published: 2026-10-06
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Heap Buffer Overflow
Action: Patch
AI Analysis

Impact

A heap‐based buffer overflow was discovered in GIMP’s DICOM export plug‑in. When an image with extremely large dimensions is exported, the plug‑in calculates the allocation size using a 32‑bit product of width, height and bytes‑per‑pixel. If this product overflows, the allocated buffer is smaller than required and GEGL writes the uncompressed image data into the undersized buffer, leading to memory corruption. The vulnerability could allow an attacker to trigger arbitrary code execution or a denial‑of‑service condition, depending on the context in which GIMP is used.

Affected Systems

The flaw affects GIMP installations bundled with Red Hat Enterprise Linux 6 through 10, including Red Hat Enterprise Linux 6, 7, 8, 9 and 10. Any system running these distributions and allowing image export to DICOM is vulnerable.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack is likely to require access to a process that performs a DICOM export, such as a local application or a service that accepts user‑supplied images. Because the CVE description does not provide evidence of remote exploitation, the risk is inferred to be lower for pure network‑based attacks but remains significant for local or privileged users.

Generated by OpenCVE AI on October 6, 2026 at 20:53 UTC.

Remediation

Vendor Workaround

To mitigate this avoid exporting untrusted or unnecessarily huge images to DICOM; cap image dimensions in workflows that process third-party content. Use checked multiplication and maximum dimension limits in custom automation that drives GIMP export.


OpenCVE Recommended Actions

  • Upgrade GIMP to the latest patched version that mitigates the buffer overflow
  • Implement strict image‑dimension checks in any workflow that exports to DICOM, capping width and height to safe limits and using checked multiplication
  • Avoid exporting untrusted or extremely large images to DICOM whenever possible
  • If an upgrade is not immediately possible, apply the workaround of limiting dimensions and validating the multiplication before allocation as described by the vendor

Generated by OpenCVE AI on October 6, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export path allocates a buffer using a 32-bit width * height (and bytes-per-pixel) product that can overflow. GEGL then writes the full uncompressed extent into the undersized buffer (CWE-787), after integer overflow in the allocation size
Title Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-119
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T19:34:29.710Z

Reserved: 2026-10-06T14:27:03.614Z

Link: CVE-2026-106063

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:17.090

Modified: 2026-10-06T20:17:17.090

Link: CVE-2026-106063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:00:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer