Skip to content
Red HatCVE-2026-78475

Red Hat GIMP: denial of service

Medium6.1CVE-2026-78475 · Published Aug 24, 2026 · updated Sep 1, 2026

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

Red Hat advisory

Affected versions

PackageAffectedFixed in
GIMP
Product
<= 3.0.0No fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
A flaw was found in CRI-O's container-creation environment-variable handling
Medium6.0Aug 24
Red Hat file-pcx plugin: integer overflow
High7.0Aug 24
Red Hat Enterprise Linux 10: improper authorization
High7.1Aug 24
Red Hat AWX: path traversal
High7.2Aug 24
Red Hat multiple AWX: server-side request forgery
High7.7Aug 24
Red Hat WebKitGTK: use after free
High8.8Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.