CVE-2026-106066mediumCWE-119

CVE-2026-106066: medium-severity vulnerability in Red Hat Enterprise Linux 10

Gimp: gimp: heap buffer overflow in raw data export on oversized image dimensions

Published

10Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.3
exploitation probability
—
observed exploitation
nono source reports it
A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far less memory than GEGL reads or writes during export, following integer overflow
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H