CVE-2026-82330
NixOS Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-82330 is a heap out-of-bounds read vulnerability in the file-pvr plugin of GIMP, affecting versions 3.2.0 and newer. When processing a specially crafted PVR image file, the VQ (compressed) decoder fails to perform proper memory bounds checking, resulting in a heap out-of-bounds read. The vulnerability was disclosed on August 28, 2026, and is assigned a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, Github Advisory). The flaw was reported by Zhixi "Jace" Sun and assigned by Red Hat as the CNA (Red Hat Advisory).

Détails techniques

The root cause is classified as CWE-125 (Out-of-bounds Read): the VQ (compressed) decoder in GIMP's file-pvr plugin does not validate memory boundaries when parsing PVR image data, allowing reads beyond the intended buffer (Red Hat Advisory, Github Advisory). Exploitation requires local access and user interaction — specifically, a victim must open a maliciously crafted PVR file within GIMP. The attack vector is local (AV:L), with low complexity and no privileges required, but user interaction is mandatory (Red Hat Advisory). The GNOME/GIMP issue tracker references this flaw at work item #16586 (Red Hat Bugzilla).

Impact

Successful exploitation can cause GIMP to crash, resulting in a denial of service, or may lead to limited disclosure of heap memory contents, which could potentially expose sensitive in-memory data such as cryptographic keys, PII, or memory addresses useful for bypassing ASLR (Red Hat Advisory). Integrity is not impacted, and the scope of the vulnerability is confined to the affected GIMP process. The practical risk is moderate: an attacker must socially engineer a user into opening a crafted PVR file, limiting the likelihood of exploitation (Red Hat Advisory).

Exploitabilité

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at this time (Github Advisory). The NVD SSVC assessment notes exploitation status as "poc" but no confirmed public PoC has been identified. The EPSS score is approximately 0.119% (2nd percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires user interaction, further reducing risk (Red Hat Advisory).

Étapes d’exploitation

  1. Craft malicious PVR file: Create a specially crafted PVR image file with malformed VQ (compressed) data that triggers the missing bounds check in GIMP's file-pvr plugin decoder.
  2. Social engineering: Deliver the crafted PVR file to a target user via email, file sharing, or a malicious website, convincing them to open it with GIMP.
  3. Trigger the vulnerability: When the victim opens the file in GIMP (version 3.2.0 or newer), the VQ decoder reads beyond the intended heap buffer boundary.
  4. Achieve impact: Depending on heap layout, the out-of-bounds read either causes GIMP to crash (denial of service) or leaks heap memory contents that may be observable via error output or crash dumps, potentially disclosing sensitive data (Red Hat Advisory, Github Advisory).

Indicateurs de compromis

  • File System: Presence of unexpected or unsolicited .pvr image files in user download directories or temporary folders.
  • Logs: GIMP crash reports or core dumps generated after opening a PVR file; application error logs referencing segmentation faults or memory access violations in the file-pvr plugin.
  • Process: Abnormal termination of the GIMP process (gimp, gimp-2.10, or gimp-3.x) shortly after opening a PVR file; crash reporter dialogs appearing unexpectedly.

Atténuation et solutions de contournement

A patch is available via the GitHub Advisory (GHSA-jf24-j29f-vrgj); users should apply the available fix for GIMP versions 3.2.0 and newer (Github Advisory). As a workaround, Red Hat recommends not opening PVR files from untrusted sources in GIMP (Red Hat Advisory). Organizations should monitor for updated GIMP packages from their Linux distribution vendors (e.g., Red Hat Enterprise Linux) and apply updates promptly when available.

Réactions de la communauté

Red Hat has rated this vulnerability as Moderate severity, noting that exploitation requires convincing a user to process a specially crafted PVR image, which reduces the likelihood of exploitation (Red Hat Advisory). The vulnerability was reported by security researcher Zhixi "Jace" Sun and acknowledged by Red Hat Product Security. No significant broader media coverage or notable community discussion has been observed beyond standard vulnerability database entries.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté NixOS Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-77801MEDIUM6.5
  • GitLab logoGitLab
  • gitlab
NonOuiAug 26, 2026
CVE-2026-82330MEDIUM6.1
  • NixOS logoNixOS
  • gimp-devel
NonNonAug 28, 2026
CVE-2026-82328MEDIUM6.1
  • NixOS logoNixOS
  • gimp:2.8::pygobject2-codegen
NonNonAug 28, 2026
CVE-2026-82324MEDIUM6.1
  • NixOS logoNixOS
  • gimp-devel-tools
NonNonAug 28, 2026
CVE-2026-7487LOW3.5
  • GitLab logoGitLab
  • gitlab-rails-19.2
NonOuiAug 26, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités