Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-66759— Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images

Quick assessment

Affected
GNOME GIMP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GNOME GIMP是GNOME基金会的一款图像编辑软件。 GNOME GIMP存在缓冲区错误漏洞,该漏洞源于file-icns插件在ICNS图像处理过程中未验证游标是否超过分配资源大小,导致越界读取,可能造成堆内容信息泄露或崩溃。

CVSS 7.1 · High EPSS 0.30% · P21

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System

Affected Version Matrix 5

VendorProduct Version RangeStatus
GNOME GIMP 2.99.14< * affected
Red Hat Red Hat Enterprise Linux 6 any unaffected
Red Hat Red Hat Enterprise Linux 7 any unaffected
Red Hat Red Hat Enterprise Linux 8 any unaffected
Red Hat Red Hat Enterprise Linux 9 2:3.0.4-4.el9_8.9< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-66759

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5
Vulnerability Title
GNOME GIMP 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GNOME GIMP是GNOME基金会的一款图像编辑软件。 GNOME GIMP存在缓冲区错误漏洞,该漏洞源于file-icns插件在ICNS图像处理过程中未验证游标是否超过分配资源大小,导致越界读取,可能造成堆内容信息泄露或崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
GNOME GIMP 2.99.14 ~ * -
Red Hat Red Hat Enterprise Linux 9 2:3.0.4-4.el9_8.9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8

II. Public POCs for CVE-2026-66759

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-66759

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-66759 (4)

Same Patch Batch · GNOME · 2026-07-27 · 3 CVEs total

CVE-2026-66758 7.8 HIGH Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted
CVE-2026-66757 5.5 MEDIUM Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi

IV. Related Vulnerabilities

V. Comments for CVE-2026-66759

No comments yet


Leave a comment