Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78465— Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 6
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GIMP 的 file-pcx 插件中发现了一个漏洞,仅影响 32 位构建版本。在处理 PCX 图像文件时,该插件会根据图像的宽度和高度以及颜色平面的数量来计算内存分配大小。如果构造的文件将颜色平面数设置为 4,并配合足够大的图像尺寸,会导致计算结果超过 32 位整数上限,引发整数溢出,从而造成基于堆的缓冲区分配过小。由于这个整数溢出问题,当插件随后将图像数据写入该过小的缓冲区时,会引发基于堆的缓冲区溢出,导致内存损坏,可能进而导致任意代码执行或服务拒绝攻击。

CVSS 7.0 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78465

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-78465

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78465

登录查看更多情报信息。

Patches & Fixes for CVE-2026-78465 (1)

Vendor Advisories for CVE-2026-78465 (1)

Other References for CVE-2026-78465 (1)

Same Patch Batch · Red Hat · 2026-08-24 · 9 CVEs total

CVE-2026-78376 8.8 HIGH Webkitgtk: use-after-free of jscvalue function parameters
CVE-2026-71366 7.7 HIGH Awx: notification backends allow ssrf and credential leakage
CVE-2026-71364 7.2 HIGH Awx: project archive extraction allows path traversal file writes
CVE-2026-19685 7.1 HIGH Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user rest
CVE-2026-78367 7.0 HIGH Rpm: rpmbuild gettarspec() crafted tar member name → macro injection
CVE-2026-78323 6.5 MEDIUM Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates
CVE-2026-78475 6.1 MEDIUM Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader
CVE-2026-17113 6.0 MEDIUM Cri-o: cri-o: unvalidated image env var causes daemon crash

IV. Related Vulnerabilities

V. Comments for CVE-2026-78465

No comments yet


Leave a comment