PT-2026-67639 · Gimp · Gimp

CVE-2026-42169

·

Published

2026-08-04

·

Updated

2026-08-20

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description A heap-buffer-overflow exists in the APNG (Animated PNG) file loader, occurring when the fcTL width exceeds the IHDR width, which causes pixel data to be written beyond the heap allocation boundary. Furthermore, a heap-based buffer overflow is present in the DDS plug-in caused by a BPP (Bits Per Pixel) mismatch within the load layer() function. These issues can be triggered by opening a specially crafted image file, which may lead to arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:50817
CVE-2026-42169
OESA-2026-3413
OESA-2026-3414
RHSA-2026:50817

Affected Products

Gimp