Impact
A flaw in GIMP\u0027s file‑pvr plugin allows a heap out‑of‑bounds read when decoding a specially crafted PVR image. The missing bounds check can cause the application to crash, resulting in a denial of service or limited disclosure of heap memory contents.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 6, 7, 8, and 9, as the GIMP package included in those distributions contains the unpatched file‑pvr plugin. No specific patch version numbers are listed, so any installed GIMP build that provides the plugin is potentially affected.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability requires an attacker to supply a crafted PVR file to a victim running GIMP, which is a local file‑based attack; an attacker could leverage this to crash the application or leak a small amount of heap data. The vulnerability is not listed in CISA\u0027s KEV catalog.
OpenCVE Enrichment