Bug 2497434 (CVE-2026-58387)

Summary: CVE-2026-58387 gimp: gimp: Heap buffer overflow in Seattle FilmWorks metadata parsing
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. In load_image(), photo_date is allocated based on an unvalidated metadata separator offset and can become a 1-byte buffer before fread() writes the full metadata span into it. This could lead to heap memory corruption, potentially resulting in denial of service or arbitrary code execution.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-06 18:59:10 UTC
Heap buffer overflow write in GIMP's Seattle FilmWorks (SFW94A) loader. In load_image() in file-seattle-filmworks.c, photo_date is allocated from metadata_len[1] without verifying that a second metadata separator exists. If metadata_len[1] remains 0, a 1-byte buffer is allocated and fread() writes the full metadata span into it.

- Function: load_image()
- File: plug-ins/common/file-seattle-filmworks.c:288-314
- Fix: https://gitlab.gnome.org/GNOME/gimp/-/commit/c1263f39
- Upstream issue: https://gitlab.gnome.org/GNOME/gimp/-/issues/16230
- Acknowledgment: bb1abu