CVE-2026-106063: Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions
A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export path allocates a buffer using a 32-bit width height (and bytes-per-pixel) product that can overflow. GEGL then writes the full uncompressed extent into the undersized buffer (CWE-787), after integer overflow in the allocation size
Other sources
Finding 3. plug-ins/common/file-dicom.c, exportimage() (~1649–1652). Wrapped width height bpp allocation; GEGL write exceeds buffer. SIGSEGV/ASan WRITE. Vector: export to DICOM on very large image (multi‑GB scale), not a small malicious download alone. CVSS tentative: AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H (6.3).
— Red Hat