
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78475 is a stack-based out-of-bounds read vulnerability in the file-pix (ESM) plugin of GIMP, affecting versions 3.0.0 and newer. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, leading to an unbounded stack allocation followed by a 21-byte stack over-read. This can result in denial of service via stack exhaustion and limited disclosure of stack memory contents written to an intermediate file. The vulnerability was disclosed on August 24, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, Github Advisory).
The root cause is classified as CWE-125 (Out-of-bounds Read), stemming from the file-pix plugin's failure to validate user-supplied image dimensions or header values before allocating a Variable-Length Array on the stack. An attacker crafts a PIX image file with malicious dimension values that cause the VLA allocation to exceed safe stack bounds, followed by a 21-byte read beyond the allocated region. Exploitation requires local access and user interaction — specifically, a victim must open the malicious PIX file in GIMP. The vulnerability was reported by researcher Zhixi "Jace" Sun and tracked in Red Hat Bugzilla as bug 2522072 (Red Hat Advisory, Red Hat Bugzilla).
Successful exploitation causes GIMP to crash due to stack exhaustion (denial of service), and may result in limited disclosure of stack memory contents written to an intermediate file, potentially exposing sensitive in-memory data such as cryptographic keys, memory addresses, or other process data. The confidentiality impact is rated Low and availability impact is rated High, with no integrity impact. The out-of-bounds read could also theoretically be leveraged to bypass ASLR or other memory protection mechanisms to aid in further exploitation, though no such chaining has been demonstrated (Red Hat Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, and NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The attack requires local access and user interaction (convincing a victim to open a crafted PIX file in GIMP), which significantly reduces the likelihood of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Red Hat Advisory, Github Advisory).
Red Hat's primary recommended mitigation is to avoid opening PIX image files from untrusted sources in GIMP. Users should update GIMP to a patched version once one becomes available — the vulnerability affects GIMP 3.0.0 and newer, and patch details were not specified at time of disclosure. Organizations should also consider restricting access to PIX file processing in environments where GIMP is deployed, and monitor for unexpected GIMP crashes. The GNOME project issue is tracked at GitLab work item 16580 (Red Hat Advisory, Github Advisory).
Red Hat, as the CNA for this vulnerability, rated it Moderate severity and acknowledged the report from researcher Zhixi "Jace" Sun. Red Hat noted that the requirement to convince a user to process a specially crafted PIX image reduces the likelihood of exploitation, justifying the moderate severity rating. No significant broader community or social media discussion has been observed beyond standard vulnerability database aggregation (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."