Skip to content
Red HatCVE-2026-78465

Red Hat file-pcx plugin: integer overflow

High7.0CVE-2026-78465 · Published Aug 24, 2026 · updated Sep 1, 2026

A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

Red Hat advisory

Affected versions

PackageAffectedFixed in
GIMP
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
A flaw was found in CRI-O's container-creation environment-variable handling
Medium6.0Aug 24
Red Hat GIMP: denial of service
Medium6.1Aug 24
Red Hat Enterprise Linux 10: improper authorization
High7.1Aug 24
Red Hat AWX: path traversal
High7.2Aug 24
Red Hat multiple AWX: server-side request forgery
High7.7Aug 24
Red Hat WebKitGTK: use after free
High8.8Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.