Impact
The vulnerability is a heap‑based buffer overflow in GIMP’s raw data export plug‑in. When an image with dimensions that produce a width × height × bytes‑per‑pixel value exceeding normal limits is exported, the g_malloc call allocates less memory than GEGL processes during export due to an integer overflow. This mismatch allows an attacker to overwrite heap memory, potentially leading to arbitrary code execution or data corruption.
Affected Systems
Affected systems include Red Hat Enterprise Linux 6 through 10 running the GIMP package; any installation that provides the raw data export plug‑in is vulnerable.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. Without an EPSS score the current exploitation likelihood is unclear, and the vulnerability is not yet listed in CISA KEV, implying no known active exploits. The exploitable condition requires a user or process to invoke GIMP’s raw export with a crafted image of extreme dimensions, which can be achieved locally or remotely if the image is processed on the victim’s system. Successful overflow could lead to code execution or other memory corruption outcomes.
OpenCVE Enrichment