Description
A heap-based buffer overflow was found in GIMP’s PCX export plug-in. For images with extremely large width and height, buffer allocation uses overflowing 32-bit width * height arithmetic while subsequent GEGL operations use the full extent, after integer overflow in size calculation
Published: 2026-10-07
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Local Code Execution
Action: Apply Patch
AI Analysis

Impact

A heap-based buffer overflow occurs in the PCX export plug‑in of GIMP. When the image width and height are extremely large, the plug‑in calculates the buffer size by multiplying 32‑bit width and height values. Because this multiplication overflows, an incorrectly sized buffer is allocated, and subsequent GEGL operations use the true image size. It is inferred that the overflow may allow an attacker to write beyond the allocated memory, potentially leading to arbitrary code execution, although the source text does not explicitly state this outcome. This issue is classified as CWE‑119.

Affected Systems

The flaw affects Red Hat Enterprise Linux distributions 6 through 10, as the vulnerable GIMP package is available on these platforms. It is inferred that any system that runs GIMP and exports large images to the PCX format would be susceptible, though this specific claim is not directly stated in the source information. The issue is not limited to a particular release of the operating system, but rather to the presence of the vulnerable GIMP plug‑in in the system’s package set.

Risk and Exploitability

The CVSS base score of 6.3 indicates a moderate severity. The EPSS score is not reported, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting that widespread exploitation may not yet be observed. The attack requires that an attacker provide a crafted image that an ordinary user or process opens and then asks GIMP to export as PCX. It is inferred that a skilled attacker might exploit the exposed memory area, potentially achieving privilege escalation on the host system, though the source does not explicitly confirm this outcome.

Generated by OpenCVE AI on October 7, 2026 at 18:57 UTC.

Remediation

Vendor Workaround

Restrict PCX export to trusted images and reasonable dimension limits


OpenCVE Recommended Actions

  • Install the latest GIMP update from Red Hat’s repositories once it becomes available, which includes the fix for the integer overflow in the PCX export plug‑in.
  • While the patch is pending, limit exported PCX files to trusted images only and enforce a realistic size threshold, such as rejecting images that exceed a width or height of 32,000 pixels, as recommended by Red Hat.
  • Disable the PCX export functionality on systems where image export is not required, or restrict the GIMP executable to users who do not need to create PCX images, thereby removing the attack surface.

Generated by OpenCVE AI on October 7, 2026 at 18:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow was found in GIMP’s PCX export plug-in. For images with extremely large width and height, buffer allocation uses overflowing 32-bit width * height arithmetic while subsequent GEGL operations use the full extent, after integer overflow in size calculation
Title Gimp: gimp: heap buffer overflow in pcx export on oversized image dimensions
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-119
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T17:36:00.502Z

Reserved: 2026-10-06T14:27:14.506Z

Link: CVE-2026-106065

cve-icon Vulnrichment

Updated: 2026-10-07T17:35:27.305Z

cve-icon NVD

Status : Received

Published: 2026-10-07T17:16:47.380

Modified: 2026-10-07T18:17:15.880

Link: CVE-2026-106065

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T19:00:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer