← All Advisories

GIMP DDS Loader Integer Overflow in 32-Bit Arithmetic Leads to Heap Overflow When Opening Crafted Image Files

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-106062

Key Details

CVECVE-2026-106062
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-08
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, and Red Hat Enterprise Linux 7
Classified asCWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL, following integer overflow in size calculations. This may allow heap corruption and, in the worst case, arbitrary code execution in the context of the GIMP process. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-106062
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-106062