Back

HIGH

Gimp: gimp:memory disclosure and denial of service via specially crafted pcx image

Published Mar 26, 2026

Description

A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).

Affected products

Remediation

Vendor solution

Users should avoid opening untrusted PCX image files with GIMP. If GIMP is not required, consider removing the `gimp` package to eliminate this attack vector.

Red Hat statement

Moderate: This flaw in GIMP's PCX file loader is due to a heap buffer over-read. Exploitation requires user interaction, specifically opening a specially crafted PCX image file. Red Hat Enterprise Linux systems are affected if GIMP is installed and used to open untrusted PCX files.

Red Hat mitigation

Users should avoid opening untrusted PCX image files with GIMP. If GIMP is not required, consider removing the `gimp` package to eliminate this attack vector.

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 26, 2026
Updated Jun 16, 2026
Reserved Mar 26, 2026
CISA Vulnrichment
Updated Mar 26, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 26, 2026
ENISA EUVD
Assigner redhat
Published Mar 26, 2026
Updated Jun 16, 2026
Exploited since n/a
EUVD-2026-16166