Red HatCVE-2026-42170
Red Hat Enterprise Linux: heap buffer overflow
High7.8CVE-2026-42170 · Published Aug 8, 2026 · updated Sep 1, 2026
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's stride causes a write past the heap buffer boundary, leading to heap metadata corruption and potential code execution.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-131
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 7 | Red Hat libvirt: user could define virtual networks to inject arbitrary | Low2.3 | No fix yet |
| Aug 7 | Red Hat dracut: command injection | High7.5 | No fix yet |
| Aug 7 | Red Hat p11-kit. A local attacker: integer overflow | Medium6.2 | No fix yet |
| Aug 7 | Red Hat fixfiles script: race condition | Medium4.4 | No fix yet |
| Aug 6 | Red Hat udisks2: privilege escalation | High7.8 | Red Hat+1 more |
| Aug 6 | Red Hat GStreamer gst-plugins-good: denial of service | High7.5 | No fix yet |