
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-82328 is a heap out-of-bounds read vulnerability in the file-ico plugin of GIMP, caused by improper validation of the used_clrs (palette count) parameter when processing specially crafted ICO image files. It affects GIMP versions up to and including 3.3.1, as well as GIMP packages shipped with Red Hat Enterprise Linux 6, 7, 8, and 9. The vulnerability was disclosed on August 28, 2026, with a patch released in GIMP 3.2.6 on September 10, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, GitHub Advisory).
The root cause is classified as CWE-125 (Out-of-bounds Read). The file-ico plugin fails to properly validate the used_clrs palette count field in ICO image headers, leading to incorrect memory bounds checking and a subsequent heap out-of-bounds read. Exploitation requires local access and user interaction — an attacker must convince a GIMP user to open a maliciously crafted ICO file. The vulnerability was reported by Zhixi "Jace" Sun and is tracked in the GNOME GitLab issue tracker (Red Hat Advisory, Red Hat Bugzilla, GNOME GitLab).
Successful exploitation can result in a GIMP application crash (denial of service) or limited disclosure of heap memory contents, which could potentially expose sensitive in-memory data such as cryptographic keys, memory addresses, or other process data. The out-of-bounds read could also be leveraged to bypass memory protection mechanisms like ASLR, potentially aiding exploitation of separate vulnerabilities. Integrity is not impacted, and the scope is limited to the affected GIMP process (Red Hat Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at this time, though the NVD SSVC assessment notes a PoC exploitation classification. The EPSS score is approximately 0.117–0.184%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is non-automatable and requires user interaction, reducing overall risk (GitHub Advisory, Red Hat Advisory).
used_clrs (palette count) value in the file header that exceeds the actual palette data present.used_clrs value and performs memory access beyond the intended buffer bounds..ico files in user download directories, temporary folders, or email attachments.gimp, gimp-2.10, or gimp-3.x) crashing unexpectedly or generating core dump files after opening an ICO file.file-ico plugin or ICO loader; system logs showing GIMP segmentation faults (SIGSEGV) or abnormal termination signals.GIMP 3.2.6, released on September 10, 2026, addresses this vulnerability (GIMP Release). Users should upgrade to GIMP 3.2.6 or later as the primary remediation. As an interim workaround, Red Hat recommends not opening ICO files from untrusted sources with GIMP; organizations may also consider disabling the file-ico plugin if ICO file support is not required for business operations (Red Hat Advisory, GitHub Advisory).
Red Hat rated this vulnerability as Moderate severity, noting that exploitation requires convincing a user to process a specially crafted ICO image, which reduces the likelihood of exploitation. Red Hat credited Zhixi "Jace" Sun for responsibly reporting the issue (Red Hat Advisory). No significant broader community or social media discussion has been identified at this time.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
gimp
devel
gimp
focal (esm-apps)
gimp
jammy
gimp
jammy (esm-apps)
gimp
noble
gimp
noble (esm-apps)
gimp
resolute
gimp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."