REDHAT-BUG-2546640: Medium severity Gnome GIMP vulnerability
Reporter: Jim Alves-Foss 1. Upstream: https://gitlab.gnome.org/GNOME/gimp/-/workitems/16801 (Finding 1). plug-ins/common/file-xmc.c, loadthumbnail() (~1032–1046): pixel buffer sized with 32-bit width height can wrap; GEGL then reads past the allocation. ASan-confirmed heap-buffer-overflow read. Vector: open/preview crafted X cursor (XMC) file (thumbnail path). Verified on GIMP 3.2.6; unpatched at report. CVSS 3.1 tentative: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H (5.5).
Affected Software
Event History
Frequently Asked Questions
What interaction is required for exploitation?
A user must open or preview a crafted X cursor (XMC) file. The issue is reached through the thumbnail-loading path.
What is the expected impact?
The reported outcome is an ASan-confirmed heap-buffer-overflow read caused by integer wrapping in pixel-buffer sizing. The tentative CVSS vector indicates availability impact only, with no stated confidentiality or integrity impact.
Which version has been verified as affected?
The issue was verified on GIMP 3.2.6. It was reported as unpatched at the time of the report.