
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-106061 is a heap buffer over-read vulnerability in GIMP's X cursor (XMC) thumbnail loader, caused by an integer overflow in 32-bit signed arithmetic during pixel buffer size calculation. When GIMP generates a thumbnail for a crafted XMC file, the width * height product can overflow, resulting in an undersized allocation; a subsequent GEGL buffer read then accesses memory beyond the allocated region. The vulnerability was reported by Jim Alves-Foss, disclosed on October 6–7, 2026, and affects GIMP (confirmed on version 3.2.6) as packaged in Red Hat Enterprise Linux. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, GitHub Advisory).
The root cause is a combination of CWE-190 (Integer Overflow) and CWE-125 (Out-of-bounds Read) in the XMC thumbnail loading code located in plug-ins/common/file-xmc.c, specifically within the load_thumbnail() function (approximately lines 1032–1046). The pixel buffer is allocated using a 32-bit signed width * height multiplication; if the product wraps around due to overflow, the allocation is smaller than the actual image data. GEGL subsequently reads using the original, unwrapped dimensions, causing a heap-based out-of-bounds read. The vulnerability is triggered locally when a user opens or previews a specially crafted XMC cursor file, and has been confirmed via AddressSanitizer (ASan) as a heap-buffer-overflow read (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation can result in a denial of service (GIMP crash) or limited disclosure of heap memory contents, potentially including sensitive data such as cryptographic keys, memory addresses, or other process data. In some scenarios, the out-of-bounds read could be leveraged to bypass memory protection mechanisms like ASLR, potentially aiding exploitation of a separate vulnerability for code execution. The scope is limited to the user's GIMP process; no privilege escalation or network-level impact is expected (Red Hat CVE).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability requires local access and user interaction — an attacker must convince a victim to open or preview a malicious XMC file in GIMP. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Red Hat CVE).
load_thumbnail() in plug-ins/common/file-xmc.c allocates a pixel buffer using the overflowed (undersized) size..xmc cursor files in user download directories, temporary folders, or email attachments./var/log/messages, journald) recording GIMP segfaults or SIGABRT signals; GNOME/desktop environment logs showing thumbnail generation failures for XMC files.file-xmc.c or the XMC thumbnail loader component.Red Hat has acknowledged the vulnerability and a patch is available via Red Hat's security channels (tracked in Bugzilla bug 2546640). Until a patched package is applied, users should avoid opening or previewing XMC cursor files from untrusted sources in GIMP, and should disable thumbnail generation for XMC files if possible. As a general precaution, only open image files from trusted sources (Red Hat CVE, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."