← All Advisories

CVE-2026-66758

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-66758

Key Details

CVECVE-2026-66758
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-190 (Integer Overflow or Wraparound)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 6
gimpgimp
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service. (NVD)

What to Do

Monitor Red Hat's and gimp's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-66758
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-66758
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-66758