A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width * height (and related) arithmetic while the filter’s pixel access path uses the true image size, after integer overflow in the allocation size

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Do not run the Hot filter (or similar heavy filters) on untrusted images with extreme dimensions; limit canvas size in untrusted workflows

History

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width * height (and related) arithmetic while the filter’s pixel access path uses the true image size, after integer overflow in the allocation size
Title Gimp: gimp: heap buffer overflow in hot color filter on oversized image
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-119
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T18:04:41.571Z

Reserved: 2026-10-06T14:27:39.430Z

Link: CVE-2026-106067

cve-icon Vulnrichment

Updated: 2026-10-07T17:58:37.098Z

cve-icon NVD

Status : Received

Published: 2026-10-07T18:17:16.173

Modified: 2026-10-07T19:17:31.853

Link: CVE-2026-106067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T19:15:14Z

Weaknesses