A heap-based buffer overflow was found in GIMP’s GIF export plug-in. Exporting an image with very large width and height can cause 32-bit overflow when computing the pixel buffer size. The plug-in allocates a buffer based on the wrapped value while GEGL writes using the true image extent, rooted in integer overflow
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Do not export untrusted high-resolution images to GIF; enforce maximum width/height in batch or scripted export pipelines
References
History
Wed, 07 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow was found in GIMP’s GIF export plug-in. Exporting an image with very large width and height can cause 32-bit overflow when computing the pixel buffer size. The plug-in allocates a buffer based on the wrapped value while GEGL writes using the true image extent, rooted in integer overflow | |
| Title | Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-119 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-07T14:34:40.565Z
Reserved: 2026-10-06T14:27:08.420Z
Link: CVE-2026-106064
No data.
Status : Awaiting Analysis
Published: 2026-10-07T15:17:08.110
Modified: 2026-10-07T15:58:17.433
Link: CVE-2026-106064
No data.
OpenCVE Enrichment
Updated: 2026-10-07T15:30:17Z
Weaknesses