CVE-2026-106066: Gimp: gimp: heap buffer overflow in raw data export on oversized image dimensions
A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, gmalloc() sizing based on overflowing width height bytes-per-pixel can allocate far less memory than GEGL reads or writes during export, following integer overflow
Other sources
Finding 6. plug-ins/common/file-raw-data.c, exportimage() (~1510–1512). PoC example W=32770, H=32768 (RGBA). ASan WRITE via geglbufferiteratereadsimple. CVSS tentative: 6.3 (AC:H).
— Red Hat