CVE-2026-78475

NameCVE-2026-78475
DescriptionA flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1145874

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gimp (PTS)bookworm, bookworm (security)2.10.34-1+deb12u10vulnerable
trixie (security), trixie3.0.4-3+deb13u10vulnerable
forky3.2.4-3vulnerable
sid3.2.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gimpsource(unstable)3.2.6-11145874

Notes

[trixie] - gimp <no-dsa> (Minor issue)
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16580
Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/27d83534e637cf160f913ac6d6388d5a5555e9d8 (GIMP_3_2_6)

Search for package or bug name: Reporting problems