CVE-2026-82328
NixOS Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-82328 is a heap out-of-bounds read vulnerability in the file-ico plugin of GIMP, caused by improper validation of the used_clrs (palette count) parameter when processing specially crafted ICO image files. The flaw affects GIMP (all versions per the Red Hat Bugzilla report), with Red Hat Enterprise Linux identified as an affected product. It was disclosed on August 28, 2026, and assigned a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, Github Advisory).

Détails techniques

The root cause is CWE-125 (Out-of-bounds Read): the file-ico plugin fails to properly validate the used_clrs palette count field in ICO image headers, leading to improper memory bounds checking and a subsequent heap out-of-bounds read. Exploitation requires a local attack vector with no privileges required, but does require user interaction — specifically, a user must open a maliciously crafted ICO file in GIMP. The vulnerability was reported by researcher Zhixi "Jace" Sun and is tracked in Red Hat Bugzilla as bug 2525612 and GNOME GitLab work item #16585 (Red Hat Advisory, Red Hat Bugzilla).

Impact

Successful exploitation can result in an application crash causing denial of service, or limited disclosure of heap memory contents that could potentially expose sensitive data such as cryptographic keys, memory addresses, or other in-memory values. The heap memory disclosure could also be leveraged to bypass ASLR and other memory protection mechanisms, potentially aiding exploitation of separate vulnerabilities. The integrity of the system is not directly affected, and the scope of impact is limited to the GIMP process itself (Red Hat Advisory).

Exploitabilité

As of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The NVD SSVC assessment notes exploitation status as "poc" but the Feedly executive summary and EUVD data confirm no public PoC exists at this time. The EPSS score is approximately 0.117% (2nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory, Red Hat Advisory).

Étapes d’exploitation

  1. Craft a malicious ICO file: Create a specially crafted ICO image file with an invalid or oversized used_clrs (palette count) value in the ICO header that exceeds the actual palette data present in the file.
  2. Social engineering: Deliver the malicious ICO file to a target user via email attachment, file share, or web download, and convince them to open it with GIMP.
  3. Trigger the vulnerability: When the user opens the file in GIMP, the file-ico plugin reads the malformed used_clrs value without proper bounds validation, causing a heap out-of-bounds read.
  4. Achieve impact: The out-of-bounds read either crashes the GIMP application (denial of service) or leaks adjacent heap memory contents, which an attacker could potentially use to infer memory layout for further exploitation (Red Hat Advisory, Red Hat Bugzilla).

Indicateurs de compromis

  • File System: Presence of unexpected or suspicious .ico files in user download directories, temporary folders, or email attachment staging areas.
  • Logs: GIMP crash reports or core dumps in /var/crash/ or ~/.cache/ directories following the opening of an ICO file; system logs showing GIMP process termination with a segmentation fault or similar memory error.
  • Process: Abnormal termination of the GIMP process (gimp-2.x) shortly after opening an ICO file, potentially visible in system logs (e.g., journalctl entries for process crashes).

Atténuation et solutions de contournement

Red Hat's primary mitigation recommendation is to avoid opening ICO files from untrusted sources with GIMP. A patch is noted as available per the GitHub Advisory Database, though specific fixed version numbers have not yet been published in the advisory. Users in production environments where availability is critical should consider restricting access to GIMP or disabling ICO file handling until a vendor-confirmed patched version is released (Red Hat Advisory, Github Advisory).

Réactions de la communauté

Red Hat rated this vulnerability as moderate severity, noting that exploitation requires convincing a user to open a crafted ICO file, which reduces the likelihood of exploitation. The vulnerability was reported by researcher Zhixi "Jace" Sun and acknowledged by Red Hat Product Security. No significant broader community or media discussion has been observed beyond standard vulnerability database aggregation (Red Hat Advisory).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté NixOS Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-77801MEDIUM6.5
  • GitLab logoGitLab
  • gitlab
NonOuiAug 26, 2026
CVE-2026-82330MEDIUM6.1
  • NixOS logoNixOS
  • gimp-devel
NonNonAug 28, 2026
CVE-2026-82328MEDIUM6.1
  • NixOS logoNixOS
  • gimp:2.8::pygobject2-codegen
NonNonAug 28, 2026
CVE-2026-82324MEDIUM6.1
  • NixOS logoNixOS
  • gimp-devel-tools
NonNonAug 28, 2026
CVE-2026-7487LOW3.5
  • GitLab logoGitLab
  • gitlab-rails-19.2
NonOuiAug 26, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités