PT-2026-80984 · Gimp · Gimp
CVE-2026-78475
·
Published
2026-08-24
·
Updated
2026-09-01
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GIMP (affected versions not specified)
Description
A flaw exists in the file-pix (ESM) plugin. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA)—an array whose size is determined at runtime—on the stack without proper bounds checking. This leads to an unbounded stack allocation and a subsequent 21-byte stack over-read, where the system reads data beyond the intended buffer boundary. This issue can result in a denial of service due to stack exhaustion or a limited disclosure of stack memory contents into an intermediate file.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gimp