REDHAT-BUG-2546654: High severity GIMP GIMP vulnerability
Published Oct 6, 2026
·Updated
Same upstream issue, Finding 2. plug-ins/common/ddsread.c, readdds() / loadlayer() (~428–1313): pitch/buffer sizing with wrapped width height (and related fields); GEGL writes past heap buffer. ASan-confirmed heap-buffer-overflow write. Vector: load crafted DDS file. Survives prior DDS fix CVE-2026-42170 (commit 7dff816) per reporter. CVSS tentative: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (7.8).
Affected Software
1 affected component
GIMP GIMP
Event History
Oct 6, 2026
Data Sourced
via Red Hat·04:11 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What does an attacker need to do to trigger the flaw?
An attacker needs to provide a crafted DDS file and have it loaded by GIMP. The tentative CVSS vector indicates local access and user interaction are required, with no privileges required.
2
Is applying the earlier DDS fix sufficient?
No. The reporter states that this issue survives the prior DDS fix for CVE-2026-42170, associated with commit 7dff816.