CVE-2026-82324
Awaiting Analysis Awaiting Analysis - Queue

Heap Out-of-Bounds Read in GIMP IFF/ILBM Plugin

Vulnerability report for CVE-2026-82324, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: redhat-SADP

Description

A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds checking, resulting in heap out-of-bounds reads. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-08-29
AI Q&A
2026-08-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnome gimp *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the file-iff (IFF/ILBM) plugin of GIMP. It occurs when processing a specially crafted IFF/ILBM image file. The plugin fails to validate the HAM row size and mishandles cases where the number of color planes (nPlanes) is zero. This leads to a row size mismatch that bypasses memory bounds checking, causing heap out-of-bounds reads.

Detection Guidance

This vulnerability is specific to the GIMP file-iff plugin and requires examining image files processed by GIMP. Detection involves monitoring for crashes or memory corruption when opening IFF/ILBM files. Check GIMP logs for errors during image processing. No direct network detection commands are applicable.

Impact Analysis

This vulnerability can cause an application crash, resulting in a denial of service. It may also lead to limited information disclosure of heap memory contents.

Compliance Impact

This vulnerability primarily impacts availability through application crashes and may cause limited information disclosure of heap memory contents. It does not directly violate GDPR or HIPAA but could contribute to non-compliance if exploited to access or disclose sensitive data processed by GIMP. Organizations handling regulated data should mitigate risks by avoiding untrusted IFF/ILBM files.

Mitigation Strategies

Update GIMP to the latest version where this flaw is patched. Avoid opening untrusted IFF/ILBM image files until patched. Disable the file-iff plugin if not needed. Monitor GIMP for crashes or memory corruption when processing images.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82324. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart