Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42170

Опубликовано: 04 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's stride causes a write past the heap buffer boundary, leading to heap metadata corruption and potential code execution.

Отчет

This heap-based buffer overflow vulnerability in the GIMP DDS plug-in could lead to heap metadata corruption and potential code execution. The flaw is triggered when a user opens a specially crafted DDS image file. Red Hat Enterprise Linux systems with GIMP installed are affected if users process untrusted DDS files.

Меры по смягчению последствий

Users should avoid opening untrusted DirectDraw Surface (DDS) image files with GIMP. As a general security practice, only process files from trusted sources. If GIMP is not essential, consider removing the gimp package to eliminate this attack vector.

Дополнительная информация

Статус:

Important
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2461726gimp: GIMP DDS plug-in heap-based buffer overflow via BPP mismatch in load_layer() (ddsread.c)

EPSS

Процентиль: 9%
0.00187
Низкий

7.8 High

CVSS3

Связанные уязвимости

ubuntu
6 дней назад

[Unknown description]

debian

Описание отсутствует

EPSS

Процентиль: 9%
0.00187
Низкий

7.8 High

CVSS3