---
id: CVE-2026-106062
title: >-
  A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS)
  loader
summary: >-
  A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS)
  loader. When loading a crafted DDS image, buffer sizes derived from width,
  height, and pitch can be computed using 32-bit arithmetic that overflows. The
  allocated …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
vendor: Red Hat
product: gimp
affected:
  - gimp (all versions)
  - gimp
  - gimp (all versions)
  - 'gimp:2.8/gimp (all versions)'
  - gimp (all versions)
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:04.903'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106062'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-106062'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2546654'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T21:20:28.979Z'
---

## Overview

A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL (CWE-787), following integer overflow in size calculations (CWE-190). This may allow heap corruption and, in the worst case, arbitrary code execution in the context of the GIMP process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
