Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-79902
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-79902 is a denial-of-service vulnerability in the Seattle FilmWorks (SFW) plugin bundled with GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without performing integer overflow checks, resulting in unbounded stack allocation and an application crash. The vulnerability affects GIMP versions up to and including 3.1.3 (fixed in 3.1.4 and later), and is also tracked against Red Hat Enterprise Linux 6, 7, 8, and 9. It was published on August 26, 2026, with a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-190 (Integer Overflow or Wraparound). The Seattle FilmWorks plugin in GIMP fails to validate integer values before using them to size a VLA on the stack, allowing a crafted SFW file to trigger an unbounded stack allocation. Exploitation requires local access and user interaction — specifically, a victim must open a malicious SFW image file in GIMP. The vulnerability was reported by Zhixi "Jace" Sun and is tracked internally by Red Hat as Bugzilla #2523512 (Red Hat Advisory, Red Hat Bugzilla, GNOME GitLab).

Impact

Successful exploitation causes GIMP to crash, resulting in a denial of service for the affected user. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability of the GIMP application. Because the attack vector is local and requires user interaction, the blast radius is confined to individual workstations where a user opens a malicious SFW file; lateral movement or data exfiltration are not applicable in this context (Red Hat Advisory, GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Red Hat Advisory). The EPSS score is approximately 0.13–0.20%, indicating a low probability of exploitation within the next 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement for user interaction (opening a crafted file), reducing the likelihood of opportunistic attacks.

Exploitation steps

  1. Craft a malicious SFW file: Create a specially crafted Seattle FilmWorks (.sfw) image file with header values designed to trigger an integer overflow when the plugin calculates the VLA size — for example, using a very large or near-maximum integer value for image dimensions or row count.
  2. Deliver the file to the target: Use social engineering, phishing, or a malicious download link to convince a GIMP user to open the crafted SFW file on a system running a vulnerable GIMP version (≤ 3.1.3).
  3. Trigger the vulnerability: When the victim opens the file in GIMP, the Seattle FilmWorks plugin processes the SFW header, performs an unchecked integer calculation, and allocates an oversized VLA on the stack.
  4. Achieve denial of service: The unbounded stack allocation causes a stack overflow, crashing the GIMP process and denying the user access to the application (Red Hat Advisory, GNOME GitLab).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .sfw files in user download directories, email attachments, or shared folders.
  • Logs: Repeated GIMP crash reports or core dumps in system logs (e.g., /var/log/syslog, journalctl) referencing the GIMP process terminating abnormally after opening an SFW file.
  • Process: GIMP process terminating unexpectedly (segmentation fault or stack overflow signal) shortly after a user opens an SFW image file.

Mitigation and workarounds

GIMP versions 3.1.4 and later contain the fix; users should upgrade to at least version 3.1.4 (GNOME GitLab). Red Hat has assessed RHEL 6, 7, 8, and 9 as unaffected for their shipped packages, so no RHEL patch is expected (Red Hat Advisory). As an interim workaround, users should avoid opening SFW image files from untrusted sources, and administrators can restrict or disable the Seattle FilmWorks plugin in GIMP deployments where SFW support is not required.

Community reactions

Red Hat rated this vulnerability as Moderate severity, noting that an attacker must convince a user to open a crafted SFW file, which reduces the likelihood of exploitation (Red Hat Advisory). The vulnerability was reported by Zhixi "Jace" Sun and acknowledged by Red Hat Product Security. No significant broader media coverage or notable researcher commentary beyond the standard advisory disclosures has been identified.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

gimp

Fixed

sid

gimp: 3.2.6-1

Fixed

trixie

gimp

Fixed

Ubuntu

Unknown

bionic (esm-apps)

gimp

Unknown

devel

gimp

Unknown

focal (esm-apps)

gimp

Unknown

jammy

gimp

Unknown

jammy (esm-apps)

gimp

Unknown

noble

gimp

Unknown

noble (esm-apps)

gimp

Unknown

resolute

gimp

Unknown

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • gcc10-binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-16-binutils.src
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management