Description
A heap-based buffer overflow was found in GIMP’s GIF export plug-in. Exporting an image with very large width and height can cause 32-bit overflow when computing the pixel buffer size. The plug-in allocates a buffer based on the wrapped value while GEGL writes using the true image extent, rooted in integer overflow
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Do not export untrusted high-resolution images to GIF; enforce maximum width/height in batch or scripted export pipelines
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 07 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow was found in GIMP’s GIF export plug-in. Exporting an image with very large width and height can cause 32-bit overflow when computing the pixel buffer size. The plug-in allocates a buffer based on the wrapped value while GEGL writes using the true image extent, rooted in integer overflow | |
| Title | Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-119 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-07T14:34:40.565Z
Reserved: 2026-10-06T14:27:08.420Z
Link: CVE-2026-106064
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer