CVE-2026-106067
Received Received - Intake

Heap Overflow in GIMP Hot Color Filter Plugin

Vulnerability report for CVE-2026-106067, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: redhat-SADP

Description

A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width * height (and related) arithmetic while the filter’s pixel access path uses the true image size, after integer overflow in the allocation size

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
gnome gimp to 2026-10-07 (exc)
gnome gimp *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-106067 is a heap-based buffer overflow in GIMP's Hot color filter plug-in. When processing extremely large images, the plug-in allocates a pixel buffer using 32-bit arithmetic that overflows, creating a smaller buffer than needed. The filter then accesses pixel data based on the true image size, causing an out-of-bounds write. This flaw requires manual application of the filter to an oversized image.

The vulnerability stems from a mismatch between the allocation size and the actual image dimensions, leading to potential memory corruption or arbitrary code execution. It is tracked under CWE-119 and has a CVSS v3 base score of 6.3.

Detection Guidance

To detect this vulnerability, monitor GIMP processes for crashes when applying the Hot color filter to large images. Check for heap corruption errors in system logs. Use commands like 'ps aux | grep gimp' to identify running GIMP instances and 'journalctl -xe' to review system logs for related errors.

Impact Analysis

Exploiting this vulnerability could allow attackers to execute arbitrary code or corrupt memory on your system. This may lead to crashes, resource exhaustion, or unauthorized access if the filter is applied to a maliciously crafted oversized image. The impact depends on user interaction, as the filter must be manually triggered.

Compliance Impact

This vulnerability primarily impacts system integrity and availability by allowing memory corruption or arbitrary code execution when processing large images with GIMP's Hot color filter. While it does not directly violate GDPR or HIPAA, it could indirectly affect compliance by enabling data breaches or unauthorized access if exploited in systems handling sensitive personal or health data.

Mitigation Strategies

Avoid using the Hot color filter on untrusted images with extreme dimensions. Limit canvas sizes in untrusted workflows. Upgrade to a supported GIMP version with the fix. Monitor for updates from GIMP maintainers and apply patches promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106067. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart