A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far less memory than GEGL reads or writes during export, following integer overflow
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Avoid raw export of untrusted or abnormally large images; validate dimensions before automated export.
References
History
Wed, 07 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far less memory than GEGL reads or writes during export, following integer overflow | |
| Title | Gimp: gimp: heap buffer overflow in raw data export on oversized image dimensions | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-119 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-07T17:36:16.209Z
Reserved: 2026-10-06T14:27:19.537Z
Link: CVE-2026-106066
No data.
Status : Received
Published: 2026-10-07T18:17:16.013
Modified: 2026-10-07T18:17:16.013
Link: CVE-2026-106066
No data.
OpenCVE Enrichment
Updated: 2026-10-07T18:30:14Z
Weaknesses