Impact
An integer overflow in GIMP’s ICO file loader can cause the calculated buffer size for an embedded PNG image to be smaller than required, resulting in a heap‑based buffer overflow when the decoded pixel data is written. An attacker who can supply a crafted ICO file may gain arbitrary code execution or trigger a crash, depending on whether the overflow can be used to overwrite function pointers or critical control data.
Affected Systems
Red Hat Enterprise Linux 6, 7, 8, and 9 ship GIMP packages that are affected by this flaw. Because the CVE does not specify an exact GIMP version range, all current RHEL releases that include the vulnerable GIMP package are potentially vulnerable until a fixed build is deployed.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, although no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user with access to the file system to open a malicious ICO file with GIMP, making the threat most acute for local or shared environments. If exploited successfully, an attacker can execute arbitrary code with the privileges of the running user, posing a significant risk in settings where users run GIMP with elevated rights.
OpenCVE Enrichment
Debian DSA