CVE-2026-0797
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-0797 is a heap-based buffer overflow vulnerability in GIMP's ICO file parser, enabling remote attackers to execute arbitrary code on affected systems. The vulnerability was reported to the vendor on December 24, 2025, and publicly disclosed by the Zero Day Initiative on January 30, 2026. The confirmed affected version is GIMP 3.2.0-rc1, with patches subsequently issued by GIMP and downstream Linux distributions. It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).

Technical details

The root cause is insufficient validation of user-supplied data length before copying it into a heap-based buffer during ICO file parsing, classified as CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write). An attacker exploits this by crafting a malicious ICO file with an oversized data field that overflows the heap buffer when processed by GIMP's ICO parser. Exploitation requires user interaction — the target must open a malicious ICO file or visit a web page that triggers GIMP's file parsing (e.g., via a browser plugin or file association). The fix is documented in GNOME GitLab commit 69cc6b1a6645dc9c4d7b484483dbe6a84b922b9c (ZDI Advisory, GNOME GitLab).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the GIMP process running as the current user, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive files accessible to the user, modify or delete data, or crash the application. While the attack vector is local (requiring the user to open a file), the threat is realistic via social engineering or malicious web content that delivers a crafted ICO file (ZDI Advisory, Red Hat Bugzilla).

Exploitability

A proof-of-concept exploit was published by the Zero Day Initiative on January 30, 2026, as part of their coordinated disclosure (ZDI Advisory). As of the time of reporting, there is no evidence of active in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.058% (low probability of near-term exploitation). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Craft a malicious ICO file: Create an ICO file with a manipulated header or data field that specifies a length value larger than the actual data, designed to trigger a heap buffer overflow in GIMP's ICO parser.
  2. Deliver the payload: Distribute the malicious ICO file via email attachment, file-sharing platform, or embed it in a web page that triggers GIMP's file association (e.g., via a download prompt or browser plugin).
  3. Induce user interaction: Social-engineer the target into opening the malicious ICO file with GIMP, or visiting a web page that automatically opens the file through a configured file handler.
  4. Trigger the overflow: When GIMP parses the ICO file, the lack of length validation causes user-supplied data to overflow the heap buffer, corrupting adjacent heap metadata or function pointers.
  5. Achieve code execution: By controlling the overflow content, the attacker redirects execution flow to a shellcode payload or ROP chain, executing arbitrary code in the context of the GIMP process (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected ICO files in download directories or temporary folders with anomalous file sizes or malformed headers; new or modified files in the user's home directory created around the time GIMP was opened.
  • Process: Unusual child processes spawned by the GIMP process (e.g., bash, sh, curl, wget, python) shortly after opening an ICO file; GIMP process crashing with segmentation faults or heap corruption errors.
  • Logs: Application crash logs or core dumps referencing GIMP's ICO file parser; system logs showing unexpected network connections originating from the GIMP process.
  • Network: Outbound connections from the GIMP process to external IP addresses, particularly after opening an ICO file from an untrusted source.

Mitigation and workarounds

GIMP has issued a patch addressing this vulnerability, with the fix available in the GNOME GitLab repository (commit 69cc6b1a6645dc9c4d7b484483dbe6a84b922b9c). Red Hat has released multiple errata addressing this issue across RHEL 8 and RHEL 9 variants, including RHSA-2026:4173 (RHEL 9), RHSA-2026:5113 (RHEL 8), and several Extended Update Support and SAP Solutions advisories (RHSA-2026:5388 through RHSA-2026:5437). Debian and AlmaLinux/Rocky Linux have also issued updates. As an interim workaround, users should avoid opening ICO files from untrusted sources and exercise caution when visiting unfamiliar web pages that may trigger GIMP file parsing (Red Hat Bugzilla, ZDI Advisory).

Community reactions

The vulnerability was credited to an anonymous researcher through the Zero Day Initiative's bug bounty program and disclosed on January 30, 2026. Social media activity was observed on Mastodon and Bluesky via security news accounts such as @thehackerwire, indicating moderate community awareness. Linux security outlets including LinuxSecurity.com and Pro-Linux.de covered the downstream distribution patches. No major vendor statements beyond the patch releases have been identified.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

gimp: 2.10.34-1+deb12u9

Fixed

sid

gimp: 3.2.0~RC3-1

Fixed

trixie

gimp: 3.0.4-3+deb13u7

Fixed

Ubuntu

Unknown

bionic (esm-apps)

gimp

Unknown

devel

gimp

Unknown

focal (esm-apps)

gimp

Unknown

jammy

gimp

Unknown

jammy (esm-apps)

gimp

Unknown

noble

gimp

Unknown

noble (esm-apps)

gimp

Unknown

resolute

gimp

Unknown

RHEL / CentOS

Fixed

RHEL 8

:appstream:gimp:2.8:8100020260312152017:4c9c024f/pygobject2-0:2.8-8100020260312152017.4c9c024f.src

Fixed

RHEL 9

:appstream:gimp-2:2.99.8-3.el9_0.5.src

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • headlamp-fips
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • argo-workflows-3.7
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-32773MEDIUM6.1
  • NixOS logoNixOS
  • spark
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management