Bug 2496582 (CVE-2026-59088) - CVE-2026-59088 gimp: GIMP: Denial of service via signed integer overflow in FLI file processing
Summary: CVE-2026-59088 gimp: GIMP: Denial of service via signed integer overflow in F...
Keywords:
Status: NEW
Alias: CVE-2026-59088
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2513089
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-02 15:36 UTC by OSIDB Bzimport
Modified: 2026-08-11 14:41 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-02 15:36:47 UTC
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16492

fli_header.width and fli_header.height are gushort (uint16). The expression
fb  = g_malloc (fli_header.width * fli_header.height);
ofb = g_malloc (fli_header.width * fli_header.height);


performs the multiplication after C integer promotion to int. When both values are 65535 the product 4,294,836,225 exceeds INT_MAX (2,147,483,647) → undefined behavior. UBSan detects this and the plug-in aborts.
Affected code
/* plug-ins/file-fli/fli-gimp.c:541-546 */
image = gimp_image_new (fli_header.width, fli_header.height, GIMP_INDEXED);

fb  = g_malloc (fli_header.width * fli_header.height);
ofb = g_malloc (fli_header.width * fli_header.height);


File: plug-ins/file-fli/fli-gimp.c:545 (and the mirror at L546, L805, L806)
Version: GIMP 3.2.4

Comment 4 Octavia 2026-08-11 14:41:37 UTC
The signed integer overflow in FLI file processing is ( https://drifthuntersonline.io ) worth tracking, especially for applications that handle untrusted image files. Since the bug is currently marked NEW with no fixed version listed, updating to the patched GIMP release once available would be the safest approach.


Note You need to log in before you can comment on or make changes to this bug.