Junglewise Threat Intelligence

CVE-2026-78465: GIMP file-pcx plugin integer overflow in memory allocation

CVE-2026-78465 · Severity: high · CVSS 7 · Published 2026-08-24

Technologies: Gimp. Vendors: Gimp.

Executive brief

GIMP is a widely-used image editing software. The PCX image file format plugin contains a flaw that affects 32-bit builds when opening specially crafted image files. An attacker can exploit this to corrupt memory, potentially allowing arbitrary code execution or causing the application to crash.

Technical details

An integer overflow vulnerability exists in GIMP's file-pcx plugin when calculating heap buffer allocation sizes for 32-bit builds. The plugin multiplies image dimensions by the number of color planes; if a crafted PCX file specifies 4 planes with sufficiently large dimensions, this calculation exceeds the 32-bit integer maximum, resulting in an undersized buffer allocation. When the plugin subsequently writes image data to this buffer, a heap-based buffer overflow occurs, potentially enabling arbitrary code execution or denial of service. The vulnerability requires processing a specially crafted PCX file and affects only 32-bit GIMP builds.

Affected products

  • GIMP GIMP

Timeline

  • 2026-08-24: disclosed

References

Related threats