Junglewise Threat Intelligence

CVE-2020-37239: GEGL libbabl double free in babl_free

CVE-2020-37239 · Severity: critical · CVSS 9.8 · Published 2026-05-16

Executive brief

libbabl is a software library used by image processing tools like GIMP to handle color and pixel conversions. A flaw in how the library manages memory allows a technical error known as a 'double free' to go undetected. This could allow an attacker to corrupt the application's memory, potentially leading to a system crash or the unauthorized execution of malicious code.

Technical details

libbabl 0.1.62 and newer versions contain a double free vulnerability (CWE-415) due to a failure in its custom memory management tracking. The library uses a 'signature' field in its BablAllocInfo structure to track whether a memory chunk is allocated or freed. However, because libbabl relies on the standard libc malloc/free internally, the libc metadata often overwrites this signature field immediately upon the first free() call. Consequently, subsequent calls to babl_free() fail to detect the double free, as the signature check is bypassed. An attacker who can influence the allocation and deallocation of pixel buffers could exploit this to achieve memory corruption and potential arbitrary code execution. While the exploit is local in nature for the library, it can be triggered remotely if the library is used by a network-facing application processing untrusted image data.

Affected products

  • GEGL libbabl 0.1.62 and newer

Timeline

  • 2020-12-14: disclosed: Initial discovery and PoC by Carter Yagemann
  • 2026-05-16: advisory: CVE published and enriched by VulnCheck

References