Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this do not open DDS files from untrusted sources (CME-1311). Exploitation may be harder on hardened systems (Full RELRO/PIE, ASLR, FORTIFY_SOURCE, heap allocator protections) but the vulnerability remains.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL (CWE-787), following integer overflow in size calculations (CWE-190). This may allow heap corruption and, in the worst case, arbitrary code execution in the context of the GIMP process. | |
| Title | Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface file | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-119 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-06T20:02:52.466Z
Reserved: 2026-10-06T14:26:58.730Z
Link: CVE-2026-106062
No data.
Status : Received
Published: 2026-10-06T21:17:04.903
Modified: 2026-10-06T21:17:04.903
Link: CVE-2026-106062
No data.
OpenCVE Enrichment
No data.
-
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer