Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78475

Опубликовано: 24 июл. 2026
Источник: redhat
CVSS3: 6.1

Описание

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

Отчет

To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted PIX image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, do not open PIX files from untrusted sources with GIMP.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpNot affected
Red Hat Enterprise Linux 7gimpNot affected
Red Hat Enterprise Linux 8gimp:2.8/gimpNot affected
Red Hat Enterprise Linux 9gimpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2522072gimp: unbounded stack VLA and 21-byte stack over-read in PIX (ESM) loader

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
24 дня назад

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

CVSS3: 6.1
nvd
24 дня назад

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

CVSS3: 6.1
debian
24 дня назад

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing ...

CVSS3: 6.1
github
24 дня назад

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

6.1 Medium

CVSS3