CVE-2026-80101
EUVD-2026-6611225.08.2026, 21:18
A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the allocated buffer size. This incorrect validation leads to improper bounds checking, causing a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents into the produced image.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gimp | gimp | 𝑥 ≤ 3.3.1 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| gimp |
| ||||||||
| gimp-devel |
| ||||||||
| gimp-lang |
| ||||||||
| libgimp-2_0-0 |
| ||||||||
| libgimpui-2_0-0 |
|
Common Weakness Enumeration