CVE-2026-78465
EUVD-2026-6493524.08.2026, 17:18
A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gimp | gimp | 3.0.0 ≤ 𝑥 ≤ 3.2.4 |
| gimp | gimp | 3.3.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| gimp |
| ||||||||
| gimp-devel |
| ||||||||
| gimp-lang |
| ||||||||
| libgimp-2_0-0 |
| ||||||||
| libgimpui-2_0-0 |
|