๐Ÿ” CVE Alert

CVE-2026-80101

MEDIUM 4.4

Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation

CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the allocated buffer size. This incorrect validation leads to improper bounds checking, causing a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents into the produced image.

CWE CWE-125
Vendor gnome
Product gimp
Published Aug 25, 2026
Last Updated Sep 2, 2026
Stay Ahead of the Next One

Get instant alerts for gnome gimp

Be the first to know when new medium vulnerabilities affecting gnome gimp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low

Affected Versions

GNOME / GIMP
All versions affected
Red Hat / Red Hat Enterprise Linux 6
All versions affected
Red Hat / Red Hat Enterprise Linux 7
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-80101 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2523738 gitlab.gnome.org: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16583

Credits

Red Hat would like to thank Zhixi "Jace" Sun for reporting this issue.