Back

MEDIUM

Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check

Published Aug 28, 2026

Description

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Affected products

Remediation

Vendor solution

To mitigate this vulnerability, do not open PVR files from untrusted sources with GIMP.

Red Hat statement

To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted PVR image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity.

Red Hat mitigation

To mitigate this vulnerability, do not open PVR files from untrusted sources with GIMP.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 28, 2026
Updated Aug 31, 2026
Reserved Aug 28, 2026
CISA Vulnrichment
Updated Aug 28, 2026
NVD
Status Analyzed
Modified Aug 31, 2026
Red Hat
Severity Moderate
Public date Jul 24, 2026