PT-2026-69208 · Gimp · Gimp

CVE-2026-42170

·

Published

2026-08-08

·

Updated

2026-09-01

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description A heap-based buffer overflow occurs in the DDS (DirectDraw Surface) file parser. The issue arises when a crafted DDS file specifies a D3D9 pixel format but provides a lower bits-per-pixel (bpp) value in the header. This causes the loader to allocate an undersized heap buffer. When the system subsequently consumes pixel data using the actual format's stride, it writes beyond the heap buffer boundary, resulting in heap metadata corruption and potential arbitrary code execution. This process occurs within the load layer() function located in ddsread.c.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42170

Affected Products

Gimp