REDHAT-BUG-2539597: Medium severity GIMP GIMP vulnerability
An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a crafted 4bpp TIM image has a palette large enough to enable promotetorgb, the loader creates an RGBA layer but allocates the row buffer using the smaller indexed-image size. The file-tim plug-in allocates width times two bytes for a two-row buffer, while geglbufferset() interprets the same buffer as RGBA data and reads width times eight bytes. This reads width times six bytes beyond the row buffer for every pair of rows. Adjacent heap contents are copied into the decoded image as pixel data, potentially exposing process memory if the resulting image is saved or shared; the invalid read may also crash the plug-in. The issue was reproduced with AddressSanitizer and differential images in GIMP 3.2.6, and the same code was present in the main branch. All versions are reported as affected. This is distinct from CVE-2026-40916, whose fix enlarged the row buffer for indexed layers but did not account for promotetorgb, and CVE-2026-59089, which addressed separate palette-size arithmetic. A patch was available, but no fixed release had been identified at the time of reporting.
Affected Software
Event History
Frequently Asked Questions
What conditions are required to trigger the flaw?
An attacker needs to supply a crafted 4bpp TIM image with a palette large enough to cause the loader to promote the image to RGB. The issue is triggered when GIMP's file-tim plug-in processes that image.
What is the practical impact of opening a malicious image?
The plug-in can read adjacent heap memory and copy it into decoded pixel data. If the resulting image is saved or shared, this may expose process memory; the invalid read can also crash the plug-in.
Are currently deployed versions affected?
All versions were reported as affected. The issue was reproduced in GIMP 3.2.6, and the same vulnerable code was reported in the main branch; no fixed release had been identified at the time of reporting.
Do the fixes for the related CVEs resolve this issue?
No. The CVE-2026-40916 fix enlarged the row buffer for indexed layers but did not handle the promote_to_rgb path, while CVE-2026-59089 addressed separate palette-size arithmetic.