{"id":"CVE-2026-96546","title":"A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader","summary":"A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. …","severity":"low","cvss":2.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":["CWE-125"],"vendor":"Red Hat","product":"gimp","affected":["gimp (all versions)","gimp","gimp (all versions)","gimp:2.8/gimp (all versions)","gimp (all versions)"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T19:19:54.373","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96546","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-96546","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539601","label":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/gimp/-/work_items/16802","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-23T19:31:04.477Z","slug":"CVE-2026-96546","body":"## Overview\n\nA one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}