Back

MEDIUM

Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation

Published Aug 25, 2026

Description

A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the allocated buffer size. This incorrect validation leads to improper bounds checking, causing a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents into the produced image.

Affected products

Remediation

Vendor solution

To mitigate this vulnerability, do not open XWD files from untrusted sources with GIMP.

Red Hat statement

To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted XWD image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity.

Red Hat mitigation

To mitigate this vulnerability, do not open XWD files from untrusted sources with GIMP.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 25, 2026
Updated Sep 2, 2026
Reserved Aug 25, 2026
CISA Vulnrichment
Updated Aug 26, 2026
NVD
Status Modified
Modified Sep 2, 2026
Red Hat
Severity Moderate
Public date Jul 24, 2026