Skip to content
Threat Feed
high advisory updated

Heap-Based Buffer Overflow in GIMP DDS Loader (CVE-2026-106062)

A heap-based buffer overflow in GIMP's DirectDraw Surface (DDS) loader allows for arbitrary code execution via a maliciously crafted image file.

CVE search metadata

CVE search record: CVE-2026-106062. Severity: high. CVSS: 7.8. KEV: no. Product: GIMP (all versions prior to fix), GIMP. Brief: Heap-Based Buffer Overflow in GIMP DDS Loader (CVE-2026-106062). Brief link: https://feed.craftedsignal.io/briefs/2026-10-gimp-dds-vulnerability/

What's new

  • 1. new product Oct 7, 16:48 via bsi

CVE-2026-106062 is a heap-based buffer overflow vulnerability residing in the DirectDraw Surface (DDS) loader component of the GNU Image Manipulation Program (GIMP). The flaw originates from an integer overflow (CWE-190) occurring during the calculation of buffer sizes based on the image's width, height, and pitch parameters. Because these calculations utilize 32-bit arithmetic, they can wrap around, resulting in an undersized memory allocation. When the GEGL (Generic Graphics Library) subsequently writes pixel data into this insufficient heap space, it triggers a buffer overflow (CWE-787). An attacker can exploit this by enticing a user to open a specially crafted DDS image file within GIMP, which may lead to heap corruption and potentially arbitrary code execution within the security context of the user running the GIMP application.

Impact

Successful exploitation of this vulnerability allows an attacker to achieve arbitrary code execution on the host system. The impact is confined to the privileges and permissions of the user account running GIMP. As GIMP is cross-platform, this vulnerability affects Windows, Linux, and macOS environments where the affected version of GIMP is deployed.

Recommendation

Prioritize the identification and patching of all GIMP installations within the enterprise. Monitor for systems where GIMP is installed and confirm the version is updated to a release containing the fix for CVE-2026-106062. If immediate patching is not possible, implement application control policies to restrict the ability of standard users to open untrusted image files from external sources.


Immediate actions

Inventory all endpoints with GIMP installed for vulnerability assessment.

IT Operations 48h

Mitigations

Upgrade GIMP to the latest version once the security update addressing CVE-2026-106062 is available.

immediate IT Operations

CVE-2026-106062