Description
A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Published: 2026-08-28
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Workaround
AI Analysis

Impact

A flaw in GIMP\u0027s file‑pvr plugin allows a heap out‑of‑bounds read when decoding a specially crafted PVR image. The missing bounds check can cause the application to crash, resulting in a denial of service or limited disclosure of heap memory contents.

Affected Systems

The vulnerability affects Red Hat Enterprise Linux 6, 7, 8, and 9, as the GIMP package included in those distributions contains the unpatched file‑pvr plugin. No specific patch version numbers are listed, so any installed GIMP build that provides the plugin is potentially affected.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability requires an attacker to supply a crafted PVR file to a victim running GIMP, which is a local file‑based attack; an attacker could leverage this to crash the application or leak a small amount of heap data. The vulnerability is not listed in CISA\u0027s KEV catalog.

Generated by OpenCVE AI on August 28, 2026 at 17:02 UTC.

Remediation

Vendor Workaround

To mitigate this vulnerability, do not open PVR files from untrusted sources with GIMP.


OpenCVE Recommended Actions

  • Apply the latest Red Hat Enterprise Linux updates that include the patched GIMP release.
  • Do not open PVR files from untrusted sources with GIMP, and configure file associations to prevent automatic processing of these files.
  • If a patch is not immediately available, limit GIMP execution to a sandbox or secured user account to reduce the impact of a potential crash.

Generated by OpenCVE AI on August 28, 2026 at 17:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Gimp
Gimp gimp
CPEs cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Gimp
Gimp gimp

Fri, 28 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.
Title Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Gimp Gimp
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-31T14:12:00.813Z

Reserved: 2026-08-28T14:38:03.836Z

Link: CVE-2026-82330

cve-icon Vulnrichment

Updated: 2026-08-28T16:07:47.994Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-28T16:18:34.347

Modified: 2026-08-31T22:14:22.510

Link: CVE-2026-82330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:17:14Z

Weaknesses