REDHAT-BUG-2522057: Buffer Overflow

Published Aug 24, 2026
·
Updated

A flaw was found in the file-pcx plugin in GIMP, affecting all versions on 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

Affected Software

1 affected component
GIMP GIMP file-pcx plugin

Event History

Aug 24, 2026
Data Sourced
via Red Hat·04:22 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which systems are affected?

Only 32-bit builds of GIMP are affected. The issue is in the file-pcx plugin.

2

What must occur for exploitation?

The vulnerable plugin must process a crafted PCX image whose color-plane count is set to 4 and whose dimensions are sufficiently large to trigger a 32-bit integer overflow.

3

What could exploitation cause?

Processing the crafted image can corrupt heap memory through a buffer overflow. This could potentially result in arbitrary code execution or denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203