Description
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.
Published: 2026-08-24
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Workaround
AI Analysis

Impact

The GIMP file-pix (ESM) plugin contains a flaw where a variable-length array is allocated on the stack without bounds checking, leading to an unbounded stack allocation and a 21‑byte stack over‑read. The over‑read can cause the stack to be corrupted or exhausted, resulting in a denial of service. Additionally, stack contents may be leaked into an intermediate file, exposing limited information about the system.

Affected Systems

Affected systems include installations of GIMP on Red Hat Enterprise Linux releases 6 through 9. The vulnerability resides in the file‑pix (ESM) plug‑in, so any GIMP installation relying on that plugin is potentially susceptible. Red Hat customers using these RHEL releases should be aware that GIMP on those platforms may be impacted.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate‑to‑ severity. EPSS is not available, and the vulnerability is not listed in CISA's KEV catalogue, suggesting no publicly known exploitation at this time. The likely attack vector is local: an attacker must supply a crafted PIX file that is opened with GIMP. The impact is limited to denial of service and potential disclosure of small amounts of stack data; remote exploitation is not implied by the available details.

Generated by OpenCVE AI on August 24, 2026 at 18:40 UTC.

Remediation

Vendor Workaround

To mitigate this vulnerability, do not open PIX files from untrusted sources with GIMP.


OpenCVE Recommended Actions

  • Upgrade GIMP to the latest release that contains the fixed file‑pix (ESM) plugin.
  • Disable the file‑pix (ESM) plugin in GIMP’s configuration or remove support for PIX files if it is not required.
  • Avoid opening PIX files from untrusted or external sources as a temporary safeguard.

Generated by OpenCVE AI on August 24, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Gimp
Gimp gimp
Vendors & Products Gimp
Gimp gimp

Mon, 24 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.
Title Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Gimp Gimp
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-25T13:46:20.344Z

Reserved: 2026-08-24T16:51:43.273Z

Link: CVE-2026-78475

cve-icon Vulnrichment

Updated: 2026-08-24T19:57:42.714Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-24T18:17:34.807

Modified: 2026-09-01T14:12:15.000

Link: CVE-2026-78475

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:10:00Z

Weaknesses