Description
A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width * height (and related) arithmetic while the filter’s pixel access path uses the true image size, after integer overflow in the allocation size
Published: 2026-10-07
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Heap buffer overflow in GIMP Hot color filter for large images
Action: Apply patch
AI Analysis

Impact

A heap-based buffer overflow exists in GIMP’s Hot color filter plug‑in. The plugin allocates a pixel buffer using 32‑bit arithmetic that multiplies width by height. If an image’s dimensions overflow this calculation, the allocated size is smaller than the true image size. Subsequent filter processing writes beyond the buffer, corrupting heap memory. This flaw can enable an attacker who supplies an oversized image to overwrite critical control data or inject malicious code.

Affected Systems

The GIMP package that ships with Red Hat Enterprise Linux versions 6 through 10 contains the vulnerable Hot filter plug‑in. The vulnerability applies to all RHEL releases that provide GIMP, regardless of how images are obtained. Any system running these distributions and using GIMP is potentially affected.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited. The likely attack vector is local use of untrusted large images: an attacker crafts an oversized image, opens it in GIMP, and triggers the overflow. Successful exploitation could lead to heap corruption and potentially arbitrary code execution or a crash.

Generated by OpenCVE AI on October 7, 2026 at 19:09 UTC.

Remediation

Vendor Workaround

Do not run the Hot filter (or similar heavy filters) on untrusted images with extreme dimensions; limit canvas size in untrusted workflows


OpenCVE Recommended Actions

  • Avoid running the Hot filter or similar heavy filters on untrusted images with extreme dimensions; limit canvas size in untrusted workflows.
  • Enforce a maximum canvas or image dimension policy in all untrusted image workflows that use GIMP or related tools.
  • Apply any official patch or update from Red Hat for the GIMP package as soon as it becomes available.

Generated by OpenCVE AI on October 7, 2026 at 19:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width * height (and related) arithmetic while the filter’s pixel access path uses the true image size, after integer overflow in the allocation size
Title Gimp: gimp: heap buffer overflow in hot color filter on oversized image
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-119
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T18:04:41.571Z

Reserved: 2026-10-06T14:27:39.430Z

Link: CVE-2026-106067

cve-icon Vulnrichment

Updated: 2026-10-07T17:58:37.098Z

cve-icon NVD

Status : Received

Published: 2026-10-07T18:17:16.173

Modified: 2026-10-07T19:17:31.853

Link: CVE-2026-106067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T19:15:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer