Description
A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.
Published: 2026-09-23
Score: 2.5 Low
EPSS: n/a
KEV: No
Impact: Denial of Service via application crash
Action: Apply Workaround
AI Analysis

Impact

A one‑byte out‑of‑bounds heap read flaw exists in GIMP’s uncompressed DDS loader. When the plug‑in processes the final pixel of a DDS file, it reads one byte past the pixel buffer unconditionally. If that byte cannot be read, the plug‑in crashes. No code execution or data exposure has been demonstrated. The effect is an application crash, classifying the vulnerability as a low‑impact denial‑of‑service flaw rather than an attacker‑controlled data disclosure or exploitation.

Affected Systems

The vulnerability affects Red Hat Enterprise Linux distributions from 6 through 10 that ship GIMP with the default file‑dds plug‑in. Users running GIMP on these RHEL versions are potentially exposed if they open uncompressed DDS images from untrusted sources.

Risk and Exploitability

The CVSS score of 2.5 indicates a low severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a limited exploitation likelihood. The only known mitigation is to avoid processing uncompressed DDS files from untrusted sources, so the practical attack surface is constrained. In the absence of a patch or workarounds beyond file filtering, the risk to confidential data or system integrity remains negligible, but the vulnerability can be exploited to crash GIMP via crafted DDS files.

Generated by OpenCVE AI on September 23, 2026 at 19:37 UTC.

Remediation

Vendor Workaround

Avoid importing uncompressed DDS images from untrusted sources. No application-level mitigation that preserves processing of untrusted DDS files is known.


OpenCVE Recommended Actions

  • Disable the file‑dds plug‑in in GIMP if processing uncompressed DDS files is unnecessary.
  • Avoid opening uncompressed DDS images from untrusted sources; use trusted image sets or validate file headers before import.
  • Monitor for GIMP crashes and consider replacing GIMP with a patched or newer version when available.

Generated by OpenCVE AI on September 23, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.
Title Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-23T18:29:08.538Z

Reserved: 2026-09-23T12:35:08.176Z

Link: CVE-2026-96546

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T19:19:54.373

Modified: 2026-09-23T19:19:54.373

Link: CVE-2026-96546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T19:45:08Z

Weaknesses