CVE-2026-78465
Reported by redhat · Published August 24, 2026
A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GNOME | GIMP | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| GNOME | GIMP | |
| Red Hat | Red Hat Enterprise Linux 8 |
Timeline
- Aug 24, 2026 CVE Published
- Aug 25, 2026 EPSS Score
- Sep 1, 2026 CVE Updated
- Sep 2, 2026 EPSS Score
- Sep 3, 2026 Security Advisory
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- vdb-entryx_refsource_REDHAT
- RHBZ#2522057 issue-trackingx_refsource_REDHAT