No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this vulnerability, do not open PCX files from untrusted sources with GIMP.
Mon, 24 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service. | |
| Title | Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-24T18:00:19.816Z
Reserved: 2026-08-24T16:22:00.262Z
Link: CVE-2026-78465
Updated: 2026-08-24T17:59:56.566Z
Status : Received
Published: 2026-08-24T17:18:20.810
Modified: 2026-08-24T18:17:34.307
Link: CVE-2026-78465
No data.
OpenCVE Enrichment
Updated: 2026-08-24T18:15:07Z