Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-82328
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-82328 is a heap out-of-bounds read vulnerability in the file-ico plugin of GIMP, caused by improper validation of the used_clrs (palette count) parameter when processing specially crafted ICO image files. It affects GIMP versions up to and including 3.3.1, as well as GIMP packages shipped with Red Hat Enterprise Linux 6, 7, 8, and 9. The vulnerability was disclosed on August 28, 2026, with a patch released in GIMP 3.2.6 on September 10, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read). The file-ico plugin fails to properly validate the used_clrs palette count field in ICO image headers, leading to incorrect memory bounds checking and a subsequent heap out-of-bounds read. Exploitation requires local access and user interaction — an attacker must convince a GIMP user to open a maliciously crafted ICO file. The vulnerability was reported by Zhixi "Jace" Sun and is tracked in the GNOME GitLab issue tracker (Red Hat Advisory, Red Hat Bugzilla, GNOME GitLab).

Impact

Successful exploitation can result in a GIMP application crash (denial of service) or limited disclosure of heap memory contents, which could potentially expose sensitive in-memory data such as cryptographic keys, memory addresses, or other process data. The out-of-bounds read could also be leveraged to bypass memory protection mechanisms like ASLR, potentially aiding exploitation of separate vulnerabilities. Integrity is not impacted, and the scope is limited to the affected GIMP process (Red Hat Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at this time, though the NVD SSVC assessment notes a PoC exploitation classification. The EPSS score is approximately 0.117–0.184%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is non-automatable and requires user interaction, reducing overall risk (GitHub Advisory, Red Hat Advisory).

Exploitation steps

  1. Craft malicious ICO file: Create a specially crafted ICO image file with an invalid or oversized used_clrs (palette count) value in the file header that exceeds the actual palette data present.
  2. Social engineering: Deliver the malicious ICO file to a target GIMP user via email attachment, file share, or web download, and convince them to open it with GIMP.
  3. Trigger the vulnerability: When GIMP's file-ico plugin processes the crafted file, it reads the unvalidated used_clrs value and performs memory access beyond the intended buffer bounds.
  4. Achieve objective: The out-of-bounds heap read either crashes the GIMP application (denial of service) or, in a more targeted scenario, leaks heap memory contents that could be used to defeat ASLR or extract sensitive in-memory data (Red Hat Advisory, Red Hat Bugzilla).

Indicators of compromise

  • File System: Presence of unexpected or suspicious .ico files in user download directories, temporary folders, or email attachments.
  • Process: GIMP process (gimp, gimp-2.10, or gimp-3.x) crashing unexpectedly or generating core dump files after opening an ICO file.
  • Logs: Application crash logs or core dumps referencing the file-ico plugin or ICO loader; system logs showing GIMP segmentation faults (SIGSEGV) or abnormal termination signals.

Mitigation and workarounds

GIMP 3.2.6, released on September 10, 2026, addresses this vulnerability (GIMP Release). Users should upgrade to GIMP 3.2.6 or later as the primary remediation. As an interim workaround, Red Hat recommends not opening ICO files from untrusted sources with GIMP; organizations may also consider disabling the file-ico plugin if ICO file support is not required for business operations (Red Hat Advisory, GitHub Advisory).

Community reactions

Red Hat rated this vulnerability as Moderate severity, noting that exploitation requires convincing a user to process a specially crafted ICO image, which reduces the likelihood of exploitation. Red Hat credited Zhixi "Jace" Sun for responsibly reporting the issue (Red Hat Advisory). No significant broader community or social media discussion has been identified at this time.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

gimp

Affected

sid

gimp: 3.2.6-1

Fixed

trixie

gimp

Affected

Ubuntu

Unknown

bionic (esm-apps)

gimp

Unknown

devel

gimp

Unknown

focal (esm-apps)

gimp

Unknown

jammy

gimp

Unknown

jammy (esm-apps)

gimp

Unknown

noble

gimp

Unknown

noble (esm-apps)

gimp

Unknown

resolute

gimp

Unknown

RHEL / CentOS

Affected

RHEL 8

gimp:2.8/gimp.src

Affected

RHEL 9

gimp.src

Affected

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • gcc10-binutils
NoNoSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management