Description
A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Published: 2026-08-28
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Workaround
AI Analysis

Impact

A flaw in GIMP’s file-ico loader allows an attacker to craft an ICO image with an invalid used_clrs count. The plugin fails to validate this value, causing a heap out-of-bounds read. The read can expose adjacent heap memory and triggers a crash, delivering a denial-of-service or limited information disclosure. The weakness is a classic memory-bounds problem (CWE-125).

Affected Systems

Red Hat Enterprise Linux releases 6 through 9 that ship the affected GIMP package are impacted. The vulnerability occurs in the GIMP application, which is commonly used via the GNOME environment on these systems. The specific package names and version ranges were not enumerated in the data, so administrators should inspect the GIMP version installed on each host.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium-severe risk. EPSS data is unavailable, which does not provide a current exploitation probability, and the vulnerability is not cataloged in CISA's KEV list. The likely attack vector is local; an attacker would need to supply a malicious ICO file that a user opens with GIMP. If the GIMP instance is run with elevated privileges, the crash could affect the system, but the primary impact remains terminal or informational. No public exploit claim is known from the information provided.

Generated by OpenCVE AI on August 28, 2026 at 17:05 UTC.

Remediation

Vendor Workaround

To mitigate this vulnerability, do not open ICO files from untrusted sources with GIMP.


OpenCVE Recommended Actions

  • Avoid opening ICO files from untrusted sources in GIMP.
  • Install the latest GIMP update that contains the fix once it is released by the vendor.
  • If an update is not yet available, consider disabling or uninstalling the file-ico plugin or the GIMP application entirely if handling ICO files is unnecessary.

Generated by OpenCVE AI on August 28, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Gimp
Gimp gimp
CPEs cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Gimp
Gimp gimp

Fri, 28 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Title Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Gimp Gimp
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-31T14:11:55.610Z

Reserved: 2026-08-28T14:10:48.683Z

Link: CVE-2026-82328

cve-icon Vulnrichment

Updated: 2026-08-28T16:07:04.960Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-28T16:18:34.213

Modified: 2026-08-31T22:15:16.947

Link: CVE-2026-82328

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:17:16Z

Weaknesses