A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-78475 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2522072 | Issue Tracking Vendor Advisory |
| https://gitlab.gnome.org/GNOME/gimp/-/work_items/16580 | Issue Tracking Vendor Advisory Mitigation |
Configurations
History
No history.
Information
Published : 2026-08-24 18:17
Updated : 2026-09-01 14:12
NVD link : CVE-2026-78475
Mitre link : CVE-2026-78475
CVE.ORG link : CVE-2026-78475
JSON object : View
Products Affected
redhat
- enterprise_linux
gimp
- gimp
CWE
CWE-125
Out-of-bounds Read
