CVE-2026-106064
Awaiting Analysis Awaiting Analysis - Queue

Heap-based Buffer Overflow in GIMP GIF Export Plugin

Vulnerability report for CVE-2026-106064, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: redhat-SADP

Description

A heap-based buffer overflow was found in GIMP’s GIF export plug-in. Exporting an image with very large width and height can cause 32-bit overflow when computing the pixel buffer size. The plug-in allocates a buffer based on the wrapped value while GEGL writes using the true image extent, rooted in integer overflow

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnome gimp *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-106064 is a heap-based buffer overflow in GIMP's GIF export feature. It occurs when exporting images with extremely large width and height dimensions. The plug-in incorrectly calculates buffer size due to a 32-bit integer overflow, causing a mismatch between allocated memory and actual image data written by GEGL. This leads to heap corruption or crashes.

Detection Guidance

To detect this vulnerability, monitor GIMP processes during GIF export operations. Look for crashes or memory corruption errors when exporting images with very large dimensions. Use tools like AddressSanitizer (ASan) to detect heap-based buffer overflows during GIF export. Check GIMP logs for segmentation faults or warnings related to pixel buffer allocation mismatches.

Impact Analysis

This vulnerability can cause arbitrary code execution, memory corruption, denial-of-service (crashes or resource exhaustion), or unauthorized memory access. It requires user interaction to trigger by exporting an oversized image to GIF format. Simply opening a crafted file is not sufficient.

Compliance Impact

This vulnerability primarily impacts data integrity and availability due to potential memory corruption or crashes during GIF export. While not directly targeting personal data, it could lead to unauthorized memory access or code execution, which may compromise systems handling sensitive data. Compliance risks arise if exploited to alter or destroy regulated data (e.g., patient records under HIPAA or personal data under GDPR). However, the vulnerability requires user interaction (exporting an oversized image), reducing the likelihood of accidental exposure.

Mitigation Strategies

Avoid exporting untrusted images with extremely large dimensions to GIF format. Implement maximum width and height limits in automated export processes. Update GIMP to the latest patched version if available. Disable the GIF export plug-in if not required. Monitor system logs for suspicious activity during image export operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106064. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart