A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allocates a pixel buffer using a width * height size computed in 32-bit signed arithmetic. If that product overflows, the allocation is smaller than the true image extent. A subsequent GEGL buffer read uses the unwrapped dimensions and performs an out-of-bounds read on the heap (CWE-125), after integer overflow in the size calculation (CWE-190). This can crash GIMP or corrupt process memory.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
To mitigate only open X cursor and other image files from trusted sources; do not preview untrusted files in GIMP.
References
History
Wed, 07 Oct 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allocates a pixel buffer using a width * height size computed in 32-bit signed arithmetic. If that product overflows, the allocation is smaller than the true image extent. A subsequent GEGL buffer read uses the unwrapped dimensions and performs an out-of-bounds read on the heap (CWE-125), after integer overflow in the size calculation (CWE-190). This can crash GIMP or corrupt process memory. | |
| Title | Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-07T02:36:51.091Z
Reserved: 2026-10-06T14:26:51.255Z
Link: CVE-2026-106061
No data.
Status : Received
Published: 2026-10-07T03:16:57.473
Modified: 2026-10-07T03:16:57.473
Link: CVE-2026-106061
No data.
OpenCVE Enrichment
No data.
Weaknesses