CVE-2025-59820: Buffer Overflow
Published Nov 26, 2025
·Updated
In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex/tga/kistgaimport.cpp (aka KisTgaImport). Control flow proceeds even when a number of pixels becomes negative.
Affected Software
1 affected component
KDE Krita<5.2.13
Event History
Nov 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-59820?
CVE-2025-59820 has a high severity due to the potential for heap-based buffer overflow which can lead to remote code execution.
2
How do I fix CVE-2025-59820?
To fix CVE-2025-59820, update KDE Krita to version 5.2.13 or later.
3
What types of files are affected by CVE-2025-59820?
CVE-2025-59820 affects manipulated TGA files loaded in KDE Krita.
4
Can CVE-2025-59820 lead to data loss?
Yes, CVE-2025-59820 could potentially lead to data loss if an exploit occurs during the loading of a malicious TGA file.
5
Is there a workaround for CVE-2025-59820?
The best workaround for CVE-2025-59820 is to avoid loading TGA files from untrusted sources until a patch is applied.