CVE-2026-66757

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This integer overflow issue results in undefined behavior, aborting the plugin and causing a denial of service.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2026-66757 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2507465 Issue Tracking Vendor Advisory
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16494 Exploit Issue Tracking Vendor Advisory
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16494 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gimp:gimp:3.2.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-27 19:17

Updated : 2026-08-10 13:45


NVD link : CVE-2026-66757

Mitre link : CVE-2026-66757

CVE.ORG link : CVE-2026-66757


JSON object : View

Products Affected

redhat

  • enterprise_linux

gimp

  • gimp
CWE
CWE-190

Integer Overflow or Wraparound