Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. https://gitlab.gnome.org/GNOME/gimp/-/work_items/16492 fli_header.width and fli_header.height are gushort (uint16). The expression fb = g_malloc (fli_header.width * fli_header.height); ofb = g_malloc (fli_header.width * fli_header.height); performs the multiplication after C integer promotion to int. When both values are 65535 the product 4,294,836,225 exceeds INT_MAX (2,147,483,647) → undefined behavior. UBSan detects this and the plug-in aborts. Affected code /* plug-ins/file-fli/fli-gimp.c:541-546 */ image = gimp_image_new (fli_header.width, fli_header.height, GIMP_INDEXED); fb = g_malloc (fli_header.width * fli_header.height); ofb = g_malloc (fli_header.width * fli_header.height); File: plug-ins/file-fli/fli-gimp.c:545 (and the mirror at L546, L805, L806) Version: GIMP 3.2.4
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle. Changing version to 45.