CVE-2026-96546 - Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader
CVE ID :CVE-2026-96546
Published : Sept. 23, 2026, 6:29 p.m. | 41 minutes ago
Description :A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.
Severity: 2.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 23, 2026, 6:29 p.m. | 41 minutes ago
Description :A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.
Severity: 2.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...