Back

HIGH

Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit

Published Aug 24, 2026

Description

A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

Affected products

Remediation

Vendor solution

To mitigate this vulnerability, do not open PCX files from untrusted sources with GIMP.

Red Hat statement

To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted PCX image with GIMP, reducing the likelihood of exploitation. However, successful exploitation may potentially lead to arbitrary code execution or a denial of service. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to this reason, this flaw has been rated with an important severity.

Red Hat mitigation

To mitigate this vulnerability, do not open PCX files from untrusted sources with GIMP.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 24, 2026
Updated Aug 31, 2026
Reserved Aug 24, 2026
CISA Vulnrichment
Updated Aug 24, 2026
NVD
Status Analyzed
Modified Sep 1, 2026
Red Hat
Severity Important
Public date Jul 24, 2026