Description
An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the larger RGBA row size. This can copy adjacent heap contents into the decoded image and may crash the plug-in.
Published: 2026-09-23
Score: 4.4 Medium
EPSS: n/a
KEV: No
Impact: Heap Out-of-Bounds Read leading to potential memory disclosure and application crash
Action: Assess Impact
AI Analysis

Impact

An out-of-bounds heap read flaw exists in the 4bpp TIM image loader of GIMP. When a crafted image causes the plug‑in to promote the data to an RGBA layer, it allocates a smaller row buffer but then processes data using a larger RGBA row size. This mismatch copies adjacent heap contents into the decoded image, enabling a memory disclosure and possibly causing the plug‑in to crash.

Affected Systems

Red Hat Enterprise Linux 6, 7, 8, 9, and 10 installations that include the GIMP package are affected. The flaw resides in the GIMP image editor component bundled with these distributions.

Risk and Exploitability

The CVSS score of 4.4 indicates a moderate risk. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, implying limited known exploitation. The likely attack vector requires a user to open a malicious TIM file. Attackers could achieve local memory disclosure and interrupt the GIMP process, potentially impacting confidentiality of local data if the leaked memory contains sensitive information.

Generated by OpenCVE AI on September 23, 2026 at 19:38 UTC.

Remediation

Vendor Workaround

Do not open TIM image files from untrusted sources. No application-level mitigation that preserves processing of untrusted TIM files is known.


OpenCVE Recommended Actions

  • Do not open TIM image files from untrusted sources
  • If the GIMP editor is not required, uninstall or disable it to eliminate the attack surface
  • Check the vendor’s release notes for an updated GIMP package that addresses the out‑of‑bounds read, and apply it as soon as it becomes available

Generated by OpenCVE AI on September 23, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the larger RGBA row size. This can copy adjacent heap contents into the decoded image and may crash the plug-in.
Title Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-23T19:30:57.589Z

Reserved: 2026-09-23T12:35:08.176Z

Link: CVE-2026-96545

cve-icon Vulnrichment

Updated: 2026-09-23T19:30:52.425Z

cve-icon NVD

Status : Received

Published: 2026-09-23T19:19:54.227

Modified: 2026-09-23T20:17:26.073

Link: CVE-2026-96545

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T19:45:08Z

Weaknesses