Skip to content
Red HatCVE-2026-82328

Red Hat file-ico plugin: out-of-bounds read

Medium6.1CVE-2026-82328 · Published Aug 28, 2026 · updated Aug 31, 2026

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Red Hat advisory

Affected versions

PackageAffectedFixed in
GIMP
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat file-psd plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat libsolv: denial of service
Medium5.5Aug 28
Red Hat file-pvr plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat GIMP: denial of service
Medium6.1Aug 28
Red Hat FFmpeg: denial of service
Medium5.4Aug 28
Red Hat Ansible Automation Platform 2: resource exhaustion
Medium5.9Aug 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.