MEDIUMVulnerability

CVE-2026-78475

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

Properties

severity
MEDIUM
score
6.1
cve_id
CVE-2026-78475
vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
published_at
2026-08-24T18:17:34.807
last_modified
2026-09-01T14:12:15.000

Related Entities (4)

AFFECTS_PRODUCT (2)

[Product]
[Product]

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Read

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78475 — Ninja Signal Threat Intelligence | Ninja Signal