Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-82328

Опубликовано: 24 июл. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Отчет

To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted ICO image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, do not open ICO files from untrusted sources with GIMP.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpOut of support scope
Red Hat Enterprise Linux 7gimpFix deferred
Red Hat Enterprise Linux 8gimp:2.8/gimpFix deferred
Red Hat Enterprise Linux 9gimpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2525612gimp: heap out-of-bounds read in ICO loader via unvalidated used_clrs palette count

EPSS

Процентиль: 8%
0.00184
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
19 дней назад

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

CVSS3: 6.1
nvd
19 дней назад

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

CVSS3: 6.1
debian
19 дней назад

A flaw was found in the file-ico plugin in GIMP. When processing a spe ...

CVSS3: 6.1
github
19 дней назад

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

EPSS

Процентиль: 8%
0.00184
Низкий

6.1 Medium

CVSS3

Уязвимость CVE-2026-82328