Impact
A one‑byte out‑of‑bounds heap read flaw exists in GIMP’s uncompressed DDS loader. When the plug‑in processes the final pixel of a DDS file, it reads one byte past the pixel buffer unconditionally. If that byte cannot be read, the plug‑in crashes. No code execution or data exposure has been demonstrated. The effect is an application crash, classifying the vulnerability as a low‑impact denial‑of‑service flaw rather than an attacker‑controlled data disclosure or exploitation.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux distributions from 6 through 10 that ship GIMP with the default file‑dds plug‑in. Users running GIMP on these RHEL versions are potentially exposed if they open uncompressed DDS images from untrusted sources.
Risk and Exploitability
The CVSS score of 2.5 indicates a low severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a limited exploitation likelihood. The only known mitigation is to avoid processing uncompressed DDS files from untrusted sources, so the practical attack surface is constrained. In the absence of a patch or workarounds beyond file filtering, the risk to confidential data or system integrity remains negligible, but the vulnerability can be exploited to crash GIMP via crafted DDS files.
OpenCVE Enrichment