PT-2026-69208 · Gimp · Gimp
CVE-2026-42170
·
Published
2026-08-08
·
Updated
2026-09-01
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GIMP (affected versions not specified)
Description
A heap-based buffer overflow occurs in the DDS (DirectDraw Surface) file parser. The issue arises when a crafted DDS file specifies a D3D9 pixel format but provides a lower bits-per-pixel (bpp) value in the header. This causes the loader to allocate an undersized heap buffer. When the system subsequently consumes pixel data using the actual format's stride, it writes beyond the heap buffer boundary, resulting in heap metadata corruption and potential arbitrary code execution. This process occurs within the
load layer() function located in ddsread.c.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gimp