REDHAT-BUG-2547459: Medium severity GIMP GIMP vulnerability
Published Oct 7, 2026
·Updated
Finding 6. plug-ins/common/file-raw-data.c, exportimage() (~1510–1512). PoC example W=32770, H=32768 (RGBA). ASan WRITE via geglbufferiteratereadsimple. CVSS tentative: 6.3 (AC:H).
Affected Software
1 affected component
GIMP GIMP
Event History
Oct 7, 2026
Data Sourced
via Red Hat·02:21 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What conditions are required to trigger the issue?
The provided proof of concept uses a very large RGBA image with width 32,770 and height 32,768 during RAW data export. The tentative CVSS assessment lists attack complexity as high.
2
What is the observed impact?
The proof of concept produced an AddressSanitizer-detected write during gegl_buffer_iterate_read_simple in export_image().
3
Which component is implicated?
The finding identifies the RAW data export implementation in plug-ins/common/file-raw-data.c, specifically export_image() around lines 1510 to 1512.