
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-82324 is a heap out-of-bounds read vulnerability in the file-iff (IFF/ILBM) plugin of GIMP, affecting versions 3.0.0 and newer (up to and including 3.3.1). The flaw was discovered and disclosed on August 28, 2026, with a patch released in GIMP 3.2.6 on September 10, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium), assigned by Red Hat as the CNA (Red Hat Advisory, GitHub Advisory).
The root cause is improper input validation (CWE-125: Out-of-bounds Read) in GIMP's IFF/ILBM image loader. Specifically, the plugin fails to properly validate the HAM (Hold-And-Modify) row size and does not correctly handle cases where the number of color planes (nPlanes) is zero, causing a row size mismatch that bypasses memory bounds checking and results in heap out-of-bounds reads (Red Hat Advisory, Red Hat Bugzilla). Exploitation requires local access and user interaction — an attacker must convince a victim to open a specially crafted IFF/ILBM image file in GIMP. The vulnerability was reported by researcher Zhixi "Jace" Sun (Red Hat Advisory).
Successful exploitation can cause GIMP to crash, resulting in a denial of service, or may lead to limited disclosure of heap memory contents, which could include sensitive data such as cryptographic keys, PII, or memory addresses useful for bypassing ASLR (Red Hat Advisory). Integrity is not impacted, and the scope is unchanged, meaning exploitation is confined to the GIMP process itself without lateral movement potential. Red Hat rates this as moderate severity due to the social engineering prerequisite required to trigger the vulnerability (Red Hat Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and NVD SSVC assessment indicates exploitation is "none" and the attack is not automatable (Feedly). The EPSS score is approximately 0.125–0.185%, placing it in a low-risk percentile for near-term exploitation (GitHub Advisory).
nPlanes set to zero to trigger the bounds-checking bypass in GIMP's file-iff plugin.file-iff plugin or IFF/ILBM file parsing..iff or .ilbm files in user download directories or temporary folders, especially from untrusted sources.GIMP released version 3.2.6 on September 10, 2026, which addresses this vulnerability; users should upgrade to this or any later version (GIMP Release). As an immediate workaround, Red Hat recommends not opening IFF/ILBM files from untrusted sources with GIMP (Red Hat Advisory). Organizations may also consider disabling or removing the IFF/ILBM plugin if it is not required for their workflows, and should educate users to avoid opening suspicious image files.
Red Hat, acting as the CNA, rated this vulnerability as moderate severity and acknowledged the social engineering requirement as a mitigating factor reducing exploitation likelihood (Red Hat Advisory). The vulnerability was reported by researcher Zhixi "Jace" Sun, credited in the Red Hat advisory. No significant broader media coverage or notable community discussion has been identified beyond standard vulnerability database entries.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
gimp
devel
gimp
focal (esm-apps)
gimp
jammy
gimp
jammy (esm-apps)
gimp
noble
gimp
noble (esm-apps)
gimp
resolute
gimp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."