GIMP Integer Overflow Vulnerability in FITS Image Loader Leading to Heap Buffer Overflow

Vulnerability

An integer overflow vulnerability has been identified in the FITS image loader of GIMP. This flaw allows remote attackers to exploit the vulnerability by providing specially crafted FITS files. The integer overflow results in a zero-byte memory allocation, which, when processing pixel data, is subjected to a heap buffer overflow. Successful exploitation of this vulnerability could cause a denial-of-service condition or potentially allow arbitrary code execution.

Impact

Exploitation of this vulnerability causes a heap buffer overflow, which can lead to memory corruption. Such buffer overflows are commonly exploited to execute arbitrary code. Additionally, the vulnerability causes a denial-of-service condition by crashing the application or consuming excessive resources.

Remediation

Users are advised to avoid opening untrusted FITS image files with GIMP. If GIMP is not needed, consider removing the application to reduce the attack surface. On Red Hat Enterprise Linux systems, GIMP can be uninstalled using the package manager.

Added: Apr 15, 2026, 9:38 PM
Updated: Apr 15, 2026, 9:38 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
3.6
remediation
8.3
relevance
6.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.