GIMP: Eight Image Handling Vulnerabilities Disclosed in Coordinated October Batch
Eight vulnerabilities impacting GIMP's image handling were disclosed between October 6-9, 2026, with severities ranging from Medium to High, stemming from integer overflow issues.

Key findings
- Eight GIMP vulnerabilities disclosed between Oct 6-9, 2026, primarily due to integer overflows in buffer size calculations.
- Vulnerabilities affect various image loaders and export plug-ins, including XCF, DDS, GIF, and DICOM.
- Heap-based buffer overflows and NULL pointer dereferences can lead to crashes or potential code execution.
- CVE-2026-106062 is rated High severity, while others are Medium.
- The common root cause across multiple CVEs is 32-bit integer overflow in width * height calculations.
On October 6-9, 2026, a batch of eight vulnerabilities was disclosed for the GNU Image Manipulation Program (GIMP), impacting various image loading and export functionalities. The vulnerabilities, ranging in severity from Medium to High, primarily stem from integer overflows in size calculations, leading to heap-based buffer overflows and NULL pointer dereferences. These flaws could allow an attacker to crash GIMP or potentially execute arbitrary code by tricking a user into opening a specially crafted image file.
Several of the disclosed vulnerabilities are related to heap-based buffer overflows occurring during image export. CVE-2026-106067 affects the Hot color filter plug-in, CVE-2026-106066 impacts the raw data export plug-in, CVE-2026-106065 is in the PCX export plug-in, CVE-2026-106064 affects the GIF export plug-in, and CVE-2026-106063 impacts the DICOM export plug-in. In each of these cases, calculations for buffer allocation based on image width and height can overflow, resulting in a buffer that is too small for the actual image data processed by GEGL.
Another group of vulnerabilities involves issues with image loading. CVE-2026-108093, a NULL pointer dereference, occurs in the XCF loader when processing image-simulation-intent and image-simulation-bpc parasites without ensuring their presence. CVE-2026-106061, a heap-based buffer overflow, is found in the X cursor (XMC) thumbnail loader due to 32-bit signed arithmetic overflow during buffer allocation. The most severe vulnerability, CVE-2026-106062, is a high-severity heap-based buffer overflow in the DirectDraw Surface (DDS) loader, where buffer sizes derived from width, height, and pitch can overflow, leading to an undersized buffer.
The disclosed vulnerabilities were reported between October 6th and October 9th, 2026. While no specific threat actor or campaign has been identified in relation to this batch of CVEs, the nature of the vulnerabilities suggests that they could be exploited by an attacker who can convince a user to open a malicious file. The impact ranges from denial-of-service (crashing the application) to potential arbitrary code execution, depending on the specific vulnerability and the context of its exploitation.
Details regarding specific affected versions and patch availability were not provided in the initial disclosure information. Users are advised to consult official GIMP security advisories for the latest information on affected versions and recommended updates. Given the range of affected components, from core loaders to various export plug-ins, applying updates promptly is crucial for mitigating the risks associated with these vulnerabilities.
This batch of eight vulnerabilities highlights ongoing challenges in securely handling image data, particularly with large image dimensions and complex file formats. The recurring theme of integer overflows in size calculations across multiple components underscores the need for robust input validation and careful arithmetic when processing external data. Users of GIMP should remain vigilant and ensure their software is updated to the latest stable version to protect against these and future security threats.
The disclosures span a three-day window, indicating a coordinated disclosure event. The severity of CVE-2026-106062 as High, alongside seven Medium-severity flaws, warrants immediate attention from GIMP users. The common root cause—integer overflow in buffer sizing—across many of these CVEs suggests a systemic issue that may have been addressed in a single update.
The vulnerabilities impact GIMP's ability to process various image formats, including XCF, Hot color filter, raw data export, PCX export, GIF export, DICOM export, X cursor (XMC), and DirectDraw Surface (DDS) files. This wide range of affected components means that users who work with diverse image types or import/export files frequently are particularly at risk if their GIMP installation is not up-to-date.
The NULL pointer dereference in CVE-2026-108093, while rated Medium, can lead to a crash, disrupting user workflows. The heap-based buffer overflows, especially the High-severity CVE-2026-106062, present a more significant risk, potentially allowing for code execution. The consistent pattern of 32-bit integer overflows in width * height calculations is a critical finding across multiple CVEs.
It is essential for GIMP users to monitor for official security advisories from the GIMP project or relevant distribution channels. Promptly applying any patches or updates released to address these vulnerabilities will be the primary defense against exploitation. The coordinated nature of this disclosure suggests that a comprehensive fix may be available or imminent.
The batch of eight CVEs disclosed between October 6-9, 2026, for GIMP underscores the importance of secure coding practices, especially in handling image processing. The recurring integer overflow vulnerability across multiple loaders and exporters necessitates a thorough review of GIMP's internal handling of image dimensions and buffer allocations. Users should prioritize updating their GIMP installations to mitigate these risks.