Skip to content
Red HatCVE-2026-66758

Red Hat file-fits plugin: integer overflow

High7.8CVE-2026-66758 · Published Jul 27, 2026 · updated Sep 2, 2026

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

Red Hat advisory

Affected versions

PackageAffectedFixed in
GIMP
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat GStreamer: out-of-bounds read
Low3.3Jul 28
Red Hat file-sgi plugin: integer overflow
Medium5.5Jul 27
Red Hat file-icns plugin: out-of-bounds read
High7.1Jul 27
Red Hat: insufficient authenticity check
High7.5Jul 27
Red Hat Enterprise Linux: out-of-bounds read
Medium5.6Jul 27
Red Hat OpenShift Virtualization 4: insecure direct object reference
High7.7Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.