Fedora Account System
Red Hat Associate
Red Hat Customer
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16492 fli_header.width and fli_header.height are gushort (uint16). The expression fb = g_malloc (fli_header.width * fli_header.height); ofb = g_malloc (fli_header.width * fli_header.height); performs the multiplication after C integer promotion to int. When both values are 65535 the product 4,294,836,225 exceeds INT_MAX (2,147,483,647) → undefined behavior. UBSan detects this and the plug-in aborts. Affected code /* plug-ins/file-fli/fli-gimp.c:541-546 */ image = gimp_image_new (fli_header.width, fli_header.height, GIMP_INDEXED); fb = g_malloc (fli_header.width * fli_header.height); ofb = g_malloc (fli_header.width * fli_header.height); File: plug-ins/file-fli/fli-gimp.c:545 (and the mirror at L546, L805, L806) Version: GIMP 3.2.4
The signed integer overflow in FLI file processing is ( https://drifthuntersonline.io ) worth tracking, especially for applications that handle untrusted image files. Since the bug is currently marked NEW with no fixed version listed, updating to the patched GIMP release once available would be the safest approach.