Skip to content
Red HatCVE-2026-66759

Red Hat file-icns plugin: out-of-bounds read

High7.1CVE-2026-66759 · Published Jul 27, 2026 · updated Aug 24, 2026

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed.

Red Hat advisory

Affected versions

PackageAffectedFixed in
GIMP
Product
<= 2.99.14No fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat GStreamer: out-of-bounds read
Low3.3Jul 28
Red Hat file-sgi plugin: integer overflow
Medium5.5Jul 27
Red Hat file-fits plugin: integer overflow
High7.8Jul 27
Red Hat: insufficient authenticity check
High7.5Jul 27
Red Hat Enterprise Linux: out-of-bounds read
Medium5.6Jul 27
Red Hat OpenShift Virtualization 4: insecure direct object reference
High7.7Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.