← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 24, 2026 · 18:17via CVEFeed

CVE-2026-78475 - Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader

Brief

CVE ID : CVE-2026-78475

Published : Aug. 24, 2026, 6:17 p. m.

  • 54 minutes ago

Description : A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read.

This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

Severity: 6.1

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed