CVE-2026-78475
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-78475 is a stack-based out-of-bounds read vulnerability in the file-pix (ESM) plugin of GIMP, affecting versions 3.0.0 and newer. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, leading to an unbounded stack allocation followed by a 21-byte stack over-read. This can result in denial of service via stack exhaustion and limited disclosure of stack memory contents written to an intermediate file. The vulnerability was disclosed on August 24, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read), stemming from the file-pix plugin's failure to validate user-supplied image dimensions or header values before allocating a Variable-Length Array on the stack. An attacker crafts a PIX image file with malicious dimension values that cause the VLA allocation to exceed safe stack bounds, followed by a 21-byte read beyond the allocated region. Exploitation requires local access and user interaction — specifically, a victim must open the malicious PIX file in GIMP. The vulnerability was reported by researcher Zhixi "Jace" Sun and tracked in Red Hat Bugzilla as bug 2522072 (Red Hat Advisory, Red Hat Bugzilla).

Impact

Successful exploitation causes GIMP to crash due to stack exhaustion (denial of service), and may result in limited disclosure of stack memory contents written to an intermediate file, potentially exposing sensitive in-memory data such as cryptographic keys, memory addresses, or other process data. The confidentiality impact is rated Low and availability impact is rated High, with no integrity impact. The out-of-bounds read could also theoretically be leveraged to bypass ASLR or other memory protection mechanisms to aid in further exploitation, though no such chaining has been demonstrated (Red Hat Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, and NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The attack requires local access and user interaction (convincing a victim to open a crafted PIX file in GIMP), which significantly reduces the likelihood of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Red Hat Advisory, Github Advisory).

Exploitation steps

  1. Craft malicious PIX file: Create a specially crafted PIX image file with manipulated header values (e.g., excessively large width or height fields) designed to trigger an unbounded VLA allocation on the stack when parsed by GIMP's file-pix (ESM) plugin.
  2. Deliver the file: Distribute the crafted PIX file to a target user via email attachment, file share, or social engineering, convincing them to open it with GIMP.
  3. Trigger the vulnerability: When the victim opens the file in GIMP, the file-pix plugin reads the malicious dimension values and allocates a VLA on the stack without bounds checking, exhausting stack memory.
  4. Achieve DoS or memory disclosure: The application crashes due to stack exhaustion (denial of service), and up to 21 bytes of stack memory may be written to an intermediate file, potentially disclosing sensitive process memory contents (Red Hat Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Process: GIMP process crashing or terminating unexpectedly when opening PIX image files; stack overflow or segmentation fault signals in system logs.
  • File System: Presence of unexpected or anomalous intermediate files in GIMP's working or temp directory containing partial stack memory contents; suspicious PIX files received from untrusted sources.
  • Logs: System crash reports or core dumps associated with the GIMP process; application error logs referencing the file-pix or ESM plugin at time of crash.

Mitigation and workarounds

Red Hat's primary recommended mitigation is to avoid opening PIX image files from untrusted sources in GIMP. Users should update GIMP to a patched version once one becomes available — the vulnerability affects GIMP 3.0.0 and newer, and patch details were not specified at time of disclosure. Organizations should also consider restricting access to PIX file processing in environments where GIMP is deployed, and monitor for unexpected GIMP crashes. The GNOME project issue is tracked at GitLab work item 16580 (Red Hat Advisory, Github Advisory).

Community reactions

Red Hat, as the CNA for this vulnerability, rated it Moderate severity and acknowledged the report from researcher Zhixi "Jace" Sun. Red Hat noted that the requirement to convince a user to process a specially crafted PIX image reduces the likelihood of exploitation, justifying the moderate severity rating. No significant broader community or social media discussion has been observed beyond standard vulnerability database aggregation (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78683CRITICAL9.4
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78682HIGH8.7
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78681HIGH8.7
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78680HIGH8.5
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78679HIGH7.1
  • Linux Debian logoLinux Debian
  • python-git
NoNoAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management