Bug 2522072 (CVE-2026-78475) - CVE-2026-78475 gimp: unbounded stack VLA and 21-byte stack over-read in PIX (ESM) loader
Summary: CVE-2026-78475 gimp: unbounded stack VLA and 21-byte stack over-read in PIX (...
Keywords:
Status: NEW
Alias: CVE-2026-78475
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2522073
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-24 16:52 UTC by OSIDB Bzimport
Modified: 2026-08-24 17:00 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-24 16:52:41 UTC
A flaw was found in the file-pix (ESM) plugin in GIMP, affecting versions 3.0.0 and newer. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.


Note You need to log in before you can comment on or make changes to this bug.