Impact
An out-of-bounds heap read flaw exists in the 4bpp TIM image loader of GIMP. When a crafted image causes the plug‑in to promote the data to an RGBA layer, it allocates a smaller row buffer but then processes data using a larger RGBA row size. This mismatch copies adjacent heap contents into the decoded image, enabling a memory disclosure and possibly causing the plug‑in to crash.
Affected Systems
Red Hat Enterprise Linux 6, 7, 8, 9, and 10 installations that include the GIMP package are affected. The flaw resides in the GIMP image editor component bundled with these distributions.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate risk. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, implying limited known exploitation. The likely attack vector requires a user to open a malicious TIM file. Attackers could achieve local memory disclosure and interrupt the GIMP process, potentially impacting confidentiality of local data if the leaked memory contains sensitive information.
OpenCVE Enrichment