Back

MEDIUM

Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0

Published Aug 28, 2026

Description

A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds checking, resulting in heap out-of-bounds reads. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Affected products

Remediation

Vendor solution

To mitigate this vulnerability, do not open IFF/ILBM files from untrusted sources with GIMP.

Red Hat statement

To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted IFF/ILBM image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity.

Red Hat mitigation

To mitigate this vulnerability, do not open IFF/ILBM files from untrusted sources with GIMP.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 28, 2026
Updated Aug 31, 2026
Reserved Aug 28, 2026
CISA Vulnrichment
Updated Aug 31, 2026
NVD
Status Analyzed
Modified Aug 31, 2026
Red Hat
Severity Moderate
Public date Aug 3, 2026