PT-2026-81853 · Gimp · Gimp

·

CVE-2026-80101

·

Published

2026-07-15

·

Updated

2026-09-02

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description A flaw in the file-xwd plugin occurs when processing specially crafted XWD image files. The plugin validates image width and bytes-per-line parameters independently instead of ensuring their combined values align with the allocated buffer size. This improper bounds checking in the load xwd f2 d1 b1() and load xwd f1 d24 b1() functions leads to a heap out-of-bounds read, which is a condition where the program reads data past the end of the intended memory buffer. This can result in an application crash causing a denial of service or a limited information disclosure of heap memory contents into the resulting image.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12701
CVE-2026-80101

Affected Products

Gimp