PT-2026-80984 · Gimp · Gimp

CVE-2026-78475

·

Published

2026-08-24

·

Updated

2026-09-01

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description A flaw exists in the file-pix (ESM) plugin. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA)—an array whose size is determined at runtime—on the stack without proper bounds checking. This leads to an unbounded stack allocation and a subsequent 21-byte stack over-read, where the system reads data beyond the intended buffer boundary. This issue can result in a denial of service due to stack exhaustion or a limited disclosure of stack memory contents into an intermediate file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78475

Affected Products

Gimp