CVE-2026-82324
NixOS Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-82324 is a heap out-of-bounds read vulnerability in the file-iff (IFF/ILBM) plugin of GIMP, affecting versions 3.0.0 and newer. The flaw arises from improper validation of the HAM row size and incorrect handling of cases where the number of color planes (nPlanes) is zero, causing a row size mismatch that bypasses memory bounds checking. It was disclosed on August 28, 2026, with Red Hat as the CNA. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat CVE, GitHub Advisory).

Détails techniques

The root cause is classified as CWE-125 (Out-of-bounds Read). The GIMP file-iff plugin fails to properly validate the HAM (Hold-And-Modify) row size when parsing IFF/ILBM image files, and does not correctly handle the edge case where nPlanes equals zero. This mismatch allows the plugin to read heap memory beyond the intended buffer boundaries. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted IFF/ILBM image file in GIMP. The issue is tracked in the GNOME GIMP issue tracker and Red Hat Bugzilla (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation can result in an application crash (denial of service) or limited disclosure of heap memory contents, which may include sensitive data such as cryptographic keys, PII, or memory addresses. Leaked memory addresses could potentially be used to bypass ASLR and other memory protection mechanisms, aiding further exploitation. The integrity of the system is not directly affected, and the scope of impact is limited to the GIMP process itself (Red Hat CVE, GitHub Advisory).

Exploitabilité

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.125% (2nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Red Hat notes that exploitation requires convincing a user to open a malicious IFF/ILBM file, which reduces the likelihood of exploitation (GitHub Advisory, Red Hat CVE).

Étapes d’exploitation

  1. Craft a malicious IFF/ILBM file: Create a specially crafted IFF/ILBM image file that sets nPlanes to zero and manipulates the HAM row size fields to trigger the bounds-check bypass in GIMP's file-iff plugin.
  2. Deliver the file to the target: Use social engineering, phishing, or a malicious download link to convince the target user to obtain the crafted image file.
  3. Induce the victim to open the file: Persuade the victim to open the crafted IFF/ILBM file with GIMP (e.g., by disguising it as a legitimate image).
  4. Trigger the out-of-bounds read: When GIMP processes the file, the plugin reads heap memory beyond the intended buffer, either crashing the application (DoS) or exposing heap memory contents to a local attacker who can observe the process output or crash dump (Red Hat CVE, Red Hat Bugzilla).

Indicateurs de compromis

  • File System: Presence of unexpected or suspicious .iff or .ilbm files in user download directories or temporary folders, particularly those with unusual file sizes or metadata.
  • Logs: GIMP crash reports or core dump files (e.g., in /var/crash/ or ~/.local/share/) generated after opening an IFF/ILBM file; application error logs referencing the file-iff plugin.
  • Process: Abnormal termination (segmentation fault) of the GIMP process (gimp-2.x or gimp-3.x) shortly after opening an image file; unexpected child process crashes related to GIMP's plug-in executor.

Atténuation et solutions de contournement

No official patch has been released as of the disclosure date; the fix status is listed as pending in Red Hat's tracker. The primary recommended mitigation is to avoid opening IFF/ILBM image files from untrusted sources in GIMP. Users may also consider disabling or restricting the file-iff plugin if IFF/ILBM support is not required for their workflows. Monitor the GIMP project and Red Hat security advisories for patch availability and apply updates promptly when released (Red Hat CVE, Red Hat Bugzilla).

Réactions de la communauté

Red Hat has rated this vulnerability as Moderate severity, citing the requirement for user interaction as a factor reducing exploitation likelihood. The vulnerability was reported by Zhixi "Jace" Sun and is being tracked in the GNOME GIMP issue tracker. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified at this time (Red Hat CVE).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté NixOS Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-77801MEDIUM6.5
  • GitLab logoGitLab
  • gitlab
NonOuiAug 26, 2026
CVE-2026-82330MEDIUM6.1
  • NixOS logoNixOS
  • gimp-devel
NonNonAug 28, 2026
CVE-2026-82328MEDIUM6.1
  • NixOS logoNixOS
  • gimp:2.8::pygobject2-codegen
NonNonAug 28, 2026
CVE-2026-82324MEDIUM6.1
  • NixOS logoNixOS
  • gimp-devel-tools
NonNonAug 28, 2026
CVE-2026-7487LOW3.5
  • GitLab logoGitLab
  • gitlab-rails-19.2
NonOuiAug 26, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités