CVE-2026-78465: Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit

Published Aug 24, 2026
·
Updated

A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

Other sources

A flaw was found in the file-pcx plugin in GIMP, affecting all versions on 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

Red Hat

Affected Software

1 affected component
GIMP=32-bit builds only

Event History

Aug 24, 2026
Data Sourced
via Red Hat·04:22 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·04:28 PM
Data Sourced
via MITRE·04:28 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are affected?

Only 32-bit GIMP builds are affected. The issue is in the file-pcx plugin when it processes PCX image files.

2

What must an attacker do to trigger the flaw?

An attacker needs to provide a crafted PCX file with four color planes and sufficiently large image dimensions. Exploitation also requires a user to open or otherwise process that file with the vulnerable plugin.

3

Are normal PCX files affected?

The described condition requires a PCX file that declares four planes and uses dimensions large enough to overflow a 32-bit allocation-size calculation. The provided information does not indicate that ordinary PCX files trigger the issue.

4

How can I determine whether I may be exposed?

Identify whether GIMP is running as a 32-bit build and whether the file-pcx plugin is available or used to process PCX files. Systems that do not process untrusted PCX content have reduced exposure, but the provided data does not include a fixed-version or patch-status indicator.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203