---
id: CVE-2026-96546
title: >-
  A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS
  image loader
summary: >-
  A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS
  image loader. When a user opens an uncompressed DDS image, the file-dds
  plug-in performs an unconditional one-byte look-ahead after processing the
  final pixel. …
severity: low
cvss: 2.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'
cwe:
  - CWE-125
vendor: Red Hat
product: gimp
affected:
  - gimp (all versions)
  - gimp
  - gimp (all versions)
  - 'gimp:2.8/gimp (all versions)'
  - gimp (all versions)
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:51:56.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96546'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-96546'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2539601'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/gimp/-/work_items/16802'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-96546.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-96546'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96546'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-09-23T19:31:04.477Z'
epss: 0.00115
epssPercentile: 0.01402
---

## Overview

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-96546.json)
