CVE-2026-106061Medium· 5.5▾ SunlitA flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allocates a pixel buffer using a width * height size computed in 32-bit signed arithmetic. If that product overflows, …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allocates a pixel buffer using a width * height size computed in 32-bit signed arithmetic. If that product overflows, the allocation is smaller than the true image extent. A subsequent GEGL buffer read uses the unwrapped dimensions and performs an out-of-bounds read on the heap (CWE-125), after integer overflow in the size calculation (CWE-190). This can crash GIMP or corrupt process memory.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96545Medium· 4.4An out-of-bounds heap read flaw was found in GIMP's TIM image loader
CVE-2026-96546Low· 2.5A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader
CVE-2026-106062High· 7.8A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader
CVE-2026-106063Medium· 6.3A heap-based buffer overflow was found in GIMP’s DICOM export plug-in
CVE-2026-104042Medium· 5.5A flaw was found in sssd
CVE-2026-104043Medium· 5.5A flaw was found in SSSD