Gimp · Gimp · CVE-2026-82328
**Name of the Vulnerable Software and Affected Versions**
GIMP (affected versions not specified)
**Description**
A flaw exists in the file-ico plugin when processing specially crafted ICO image files. The plugin fails to properly validate the `used clrs` (palette count) parameter, leading to improper memory bounds checking and a heap out-of-bounds read. This can result in an application crash, causing a denial of service or limited information disclosure of heap memory contents.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.