Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-82324
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-82324 is a heap out-of-bounds read vulnerability in the file-iff (IFF/ILBM) plugin of GIMP, affecting versions 3.0.0 and newer (up to and including 3.3.1). The flaw was discovered and disclosed on August 28, 2026, with a patch released in GIMP 3.2.6 on September 10, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium), assigned by Red Hat as the CNA (Red Hat Advisory, GitHub Advisory).

Technical details

The root cause is improper input validation (CWE-125: Out-of-bounds Read) in GIMP's IFF/ILBM image loader. Specifically, the plugin fails to properly validate the HAM (Hold-And-Modify) row size and does not correctly handle cases where the number of color planes (nPlanes) is zero, causing a row size mismatch that bypasses memory bounds checking and results in heap out-of-bounds reads (Red Hat Advisory, Red Hat Bugzilla). Exploitation requires local access and user interaction — an attacker must convince a victim to open a specially crafted IFF/ILBM image file in GIMP. The vulnerability was reported by researcher Zhixi "Jace" Sun (Red Hat Advisory).

Impact

Successful exploitation can cause GIMP to crash, resulting in a denial of service, or may lead to limited disclosure of heap memory contents, which could include sensitive data such as cryptographic keys, PII, or memory addresses useful for bypassing ASLR (Red Hat Advisory). Integrity is not impacted, and the scope is unchanged, meaning exploitation is confined to the GIMP process itself without lateral movement potential. Red Hat rates this as moderate severity due to the social engineering prerequisite required to trigger the vulnerability (Red Hat Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and NVD SSVC assessment indicates exploitation is "none" and the attack is not automatable (Feedly). The EPSS score is approximately 0.125–0.185%, placing it in a low-risk percentile for near-term exploitation (GitHub Advisory).

Exploitation steps

  1. Craft malicious IFF/ILBM file: Create a specially crafted IFF/ILBM image file with a malformed HAM row size or with nPlanes set to zero to trigger the bounds-checking bypass in GIMP's file-iff plugin.
  2. Social engineering: Deliver the crafted image to a target user via email, file sharing, or a malicious website, convincing them to open it with GIMP.
  3. Trigger the vulnerability: When the victim opens the file in GIMP, the IFF/ILBM plugin processes the malformed image, causing a heap out-of-bounds read due to the row size mismatch.
  4. Achieve impact: The out-of-bounds read results in either an application crash (denial of service) or, in a more targeted scenario, leakage of heap memory contents that could be used to defeat memory protections such as ASLR (Red Hat Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Process: GIMP process crashing unexpectedly or producing segmentation faults when opening IFF/ILBM image files.
  • Logs: Application crash logs or core dumps associated with the GIMP process, particularly referencing the file-iff plugin or IFF/ILBM file parsing.
  • File System: Presence of unexpected or suspicious .iff or .ilbm files in user download directories or temporary folders, especially from untrusted sources.

Mitigation and workarounds

GIMP released version 3.2.6 on September 10, 2026, which addresses this vulnerability; users should upgrade to this or any later version (GIMP Release). As an immediate workaround, Red Hat recommends not opening IFF/ILBM files from untrusted sources with GIMP (Red Hat Advisory). Organizations may also consider disabling or removing the IFF/ILBM plugin if it is not required for their workflows, and should educate users to avoid opening suspicious image files.

Community reactions

Red Hat, acting as the CNA, rated this vulnerability as moderate severity and acknowledged the social engineering requirement as a mitigating factor reducing exploitation likelihood (Red Hat Advisory). The vulnerability was reported by researcher Zhixi "Jace" Sun, credited in the Red Hat advisory. No significant broader media coverage or notable community discussion has been identified beyond standard vulnerability database entries.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

gimp

Affected

sid

gimp: 3.2.6-1

Fixed

trixie

gimp

Affected

Ubuntu

Unknown

bionic (esm-apps)

gimp

Unknown

devel

gimp

Unknown

focal (esm-apps)

gimp

Unknown

jammy

gimp

Unknown

jammy (esm-apps)

gimp

Unknown

noble

gimp

Unknown

noble (esm-apps)

gimp

Unknown

resolute

gimp

Unknown

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

gimp.src

Affected

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • seal-binutils
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management