Back

MEDIUM

Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count

Published Aug 28, 2026

Description

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Affected products

Remediation

Vendor solution

To mitigate this vulnerability, do not open ICO files from untrusted sources with GIMP.

Red Hat statement

To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted ICO image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity.

Red Hat mitigation

To mitigate this vulnerability, do not open ICO files from untrusted sources with GIMP.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 28, 2026
Updated Aug 31, 2026
Reserved Aug 28, 2026
CISA Vulnrichment
Updated Aug 28, 2026
NVD
Status Analyzed
Modified Aug 31, 2026
Red Hat
Severity Moderate
Public date Jul 24, 2026