Skip to content
Red HatCVE-2026-42169

Red Hat Enterprise Linux: heap buffer overflow

High7.3CVE-2026-42169 · Published Aug 4, 2026 · updated Aug 6, 2026

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat SSSD: out-of-bounds read
Medium5.5Aug 4
Red Hat Enterprise Linux 10: server-side request forgery
Medium5.4Aug 4
Red Hat Enterprise Linux 10: out-of-bounds read
Medium6.5Aug 4
Red Hat Build of Keycloak: improper signature check
Low3.7Aug 4
Red Hat popt: code execution
Low2.5Aug 4
Red Hat SSSD: uninitialized resource
Low3.3Aug 4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.