CVE-2026-96545: Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader

Published Sep 23, 2026
·
Updated

An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a crafted 4bpp TIM image has a palette large enough to enable promotetorgb, the loader creates an RGBA layer but allocates the row buffer using the smaller indexed-image size. The file-tim plug-in allocates width times two bytes for a two-row buffer, while geglbufferset() interprets the same buffer as RGBA data and reads width times eight bytes. This reads width times six bytes beyond the row buffer for every pair of rows. Adjacent heap contents are copied into the decoded image as pixel data, potentially exposing process memory if the resulting image is saved or shared; the invalid read may also crash the plug-in. The issue was reproduced with AddressSanitizer and differential images in GIMP 3.2.6, and the same code was present in the main branch. All versions are reported as affected. This is distinct from CVE-2026-40916, whose fix enlarged the row buffer for indexed layers but did not account for promotetorgb, and CVE-2026-59089, which addressed separate palette-size arithmetic. A patch was available, but no fixed release had been identified at the time of reporting.

Other sources

An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the larger RGBA row size. This can copy adjacent heap contents into the decoded image and may crash the plug-in.

MITRE

Affected Software

1 affected component
GIMP GIMP

Event History

Sep 23, 2026
Data Sourced
via Red Hat·05:59 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Users who open crafted 4bpp TIM images in GIMP are exposed. The issue can disclose adjacent process heap contents through decoded image pixels and may crash the file-tim plug-in.

2

What must an attacker provide to trigger the flaw?

An attacker needs to convince a user to open a specially crafted 4bpp TIM image whose palette is large enough to trigger promote_to_rgb. User interaction is required, while no privileges are required.

3

Are default installations affected?

All versions are reported as affected, including GIMP 3.2.6 and the main branch. No fixed release had been identified at the time of reporting, although a patch was available.

4

How can I determine whether an image may have exposed data?

The flaw occurs when a crafted 4bpp TIM image triggers promotion to RGB, causing bytes beyond the allocated row buffer to be copied into the decoded image. If the resulting image was saved or shared, its pixel data could contain adjacent heap contents from the GIMP process.

5

What can be done until a fixed release is available?

Avoid opening untrusted 4bpp TIM images, particularly those that may contain large palettes. Do not save or share images decoded from untrusted TIM files, because the output may include unintended process-memory data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203