Bug 2461725 (CVE-2026-42169) - CVE-2026-42169 gimp: GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c)
Summary: CVE-2026-42169 gimp: GIMP APNG loader heap-buffer-overflow when fcTL width ex...
Keywords:
Status: NEW
Alias: CVE-2026-42169
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-24 20:54 UTC by OSIDB Bzimport
Modified: 2026-08-05 15:05 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:50817 0 None None None 2026-08-05 15:05:04 UTC

Description OSIDB Bzimport 2026-04-24 20:54:35 UTC
A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.

Comment 2 errata-xmlrpc 2026-08-05 15:05:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:50817 https://access.redhat.com/errata/RHSA-2026:50817


Note You need to log in before you can comment on or make changes to this bug.