REDHAT-BUG-2525612: Medium severity GIMP file-ico plugin vulnerability

Published Aug 28, 2026
·
Updated

A flaw was found in the file-ico plugin in GIMP, affecting all versions. When processing a specially crafted ICO image file, the plugin does not properly validate the usedclrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Affected Software

1 affected component
GIMP file-ico plugin=all versions

Event History

Aug 28, 2026
Data Sourced
via Red Hat·02:11 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which installations are affected?

All versions of GIMP are affected when the file-ico plugin is present and processes ICO image files.

2

What does exploitation require?

An attacker needs to cause GIMP to process a specially crafted ICO image whose used_clrs palette-count parameter triggers the plugin's insufficient bounds validation.

3

What is the likely impact?

The flaw can cause an application crash, resulting in denial of service. It may also allow limited disclosure of heap memory contents through a heap out-of-bounds read.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203