Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58386

Опубликовано: 11 апр. 2026
Источник: redhat
CVSS3: 7.3

Описание

A flaw was found in GIMP's TIM loader. File-controlled width, height, and palette size values are used directly in multiple variable-length array declarations in load_image(), allowing a crafted TIM file to force oversized stack allocations and memory corruption. This could lead to denial of service or arbitrary code execution.

Отчет

A flaw was found in GIMP's TIM loader. The load_image() function uses file-controlled dimensions directly in stack-based variable-length arrays, which can lead to oversized stack allocations and memory corruption when a user opens a specially crafted TIM file.

Меры по смягчению последствий

None — requires opening a crafted TIM file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpNot affected
Red Hat Enterprise Linux 7gimpNot affected
Red Hat Enterprise Linux 8gimp:2.8/gimpNot affected
Red Hat Enterprise Linux 9gimpNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2497433gimp: gimp: Stack overflow via VLAs in load_image()

7.3 High

CVSS3

Связанные уязвимости

ubuntu
26 дней назад

[Unknown description]

debian

Описание отсутствует

7.3 High

CVSS3