Impact
A flaw in GIMP’s file-ico loader allows an attacker to craft an ICO image with an invalid used_clrs count. The plugin fails to validate this value, causing a heap out-of-bounds read. The read can expose adjacent heap memory and triggers a crash, delivering a denial-of-service or limited information disclosure. The weakness is a classic memory-bounds problem (CWE-125).
Affected Systems
Red Hat Enterprise Linux releases 6 through 9 that ship the affected GIMP package are impacted. The vulnerability occurs in the GIMP application, which is commonly used via the GNOME environment on these systems. The specific package names and version ranges were not enumerated in the data, so administrators should inspect the GIMP version installed on each host.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium-severe risk. EPSS data is unavailable, which does not provide a current exploitation probability, and the vulnerability is not cataloged in CISA's KEV list. The likely attack vector is local; an attacker would need to supply a malicious ICO file that a user opens with GIMP. If the GIMP instance is run with elevated privileges, the crash could affect the system, but the primary impact remains terminal or informational. No public exploit claim is known from the information provided.
OpenCVE Enrichment