Description
A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far less memory than GEGL reads or writes during export, following integer overflow
Published: 2026-10-07
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Potential arbitrary code execution via large image export
Action: Mitigate
AI Analysis

Impact

The vulnerability is a heap‑based buffer overflow in GIMP’s raw data export plug‑in. When an image with dimensions that produce a width × height × bytes‑per‑pixel value exceeding normal limits is exported, the g_malloc call allocates less memory than GEGL processes during export due to an integer overflow. This mismatch allows an attacker to overwrite heap memory, potentially leading to arbitrary code execution or data corruption.

Affected Systems

Affected systems include Red Hat Enterprise Linux 6 through 10 running the GIMP package; any installation that provides the raw data export plug‑in is vulnerable.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. Without an EPSS score the current exploitation likelihood is unclear, and the vulnerability is not yet listed in CISA KEV, implying no known active exploits. The exploitable condition requires a user or process to invoke GIMP’s raw export with a crafted image of extreme dimensions, which can be achieved locally or remotely if the image is processed on the victim’s system. Successful overflow could lead to code execution or other memory corruption outcomes.

Generated by OpenCVE AI on October 7, 2026 at 18:28 UTC.

Remediation

Vendor Workaround

Avoid raw export of untrusted or abnormally large images; validate dimensions before automated export.


OpenCVE Recommended Actions

  • Validate image dimensions before any raw export operation and reject files that exceed reasonable thresholds; this implements the official workaround.
  • If a patched version of GIMP that repairs the g_malloc sizing issue is available, install the latest package from the vendor or upstream source.
  • Disable or uninstall the raw data export plug‑in if it is not required for normal workflow, reducing the attack surface.

Generated by OpenCVE AI on October 7, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far less memory than GEGL reads or writes during export, following integer overflow
Title Gimp: gimp: heap buffer overflow in raw data export on oversized image dimensions
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-119
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T19:24:30.471Z

Reserved: 2026-10-06T14:27:19.537Z

Link: CVE-2026-106066

cve-icon Vulnrichment

Updated: 2026-10-07T19:24:27.151Z

cve-icon NVD

Status : Received

Published: 2026-10-07T18:17:16.013

Modified: 2026-10-07T20:17:08.370

Link: CVE-2026-106066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T18:30:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer