CVE-2026-106061
Received Received - Intake

Integer Overflow Leading to Heap Out-of-Bounds Read in GIMP XMC Thumbnail Loader

Vulnerability report for CVE-2026-106061, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: redhat-SADP

Description

A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allocates a pixel buffer using a width * height size computed in 32-bit signed arithmetic. If that product overflows, the allocation is smaller than the true image extent. A subsequent GEGL buffer read uses the unwrapped dimensions and performs an out-of-bounds read on the heap (CWE-125), after integer overflow in the size calculation (CWE-190). This can crash GIMP or corrupt process memory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnome gimp 3.2.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in GIMP's X cursor (XMC) thumbnail loader. When GIMP processes a specially crafted XMC file, it calculates the size of a pixel buffer using 32-bit arithmetic. If the width multiplied by height overflows, the allocated buffer is too small. This leads to an out-of-bounds heap read when GEGL processes the image, potentially crashing GIMP or corrupting memory.

Detection Guidance

Detecting this vulnerability requires checking for GIMP installations and analyzing XMC files for malicious content. Use commands like 'which gimp' to locate GIMP, then inspect XMC files with 'file' or 'hexdump' for unusual structures. Enable AddressSanitizer (ASan) in GIMP builds to detect heap buffer overflows during thumbnail processing.

Impact Analysis

An attacker could trick you into opening or previewing a malicious XMC file. This may crash GIMP, corrupt memory, or leak sensitive data from your system. The impact is limited to local attacks requiring user interaction, with no remote code execution or privilege escalation.

Compliance Impact

This vulnerability primarily impacts availability by crashing GIMP or corrupting memory. It does not directly affect confidentiality or integrity of data. Compliance impact would depend on whether GIMP is used in regulated environments, but no specific compliance violations are directly caused by this issue.

Mitigation Strategies

Avoid opening or previewing X cursor (XMC) files from untrusted sources. Disable thumbnail previews for XMC files in GIMP settings. Update GIMP to the latest patched version once available. Monitor GIMP processes for crashes or memory corruption when handling XMC files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106061. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart