Medium severity6.1OSV Advisory· Published Jun 13, 2025· Updated Jun 30, 2026
CVE-2025-6035
CVE-2025-6035
Description
A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image dimensions, such as width, height, and bytes-per-pixel (img_bpp), which can result in allocating insufficient memory and subsequently performing out-of-bounds writes. This issue could lead to heap corruption, a potential denial of service (DoS), or arbitrary code execution in certain scenarios.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9BASE_ZERO, BEFORE_GIMAGE_IS_FLAT_REMOVAL, BEFORE_MATTS_CRAZY_TOOL_PATCH, …+ 1 more
- (no CPE)range: BASE_ZERO, BEFORE_GIMAGE_IS_FLAT_REMOVAL, BEFORE_MATTS_CRAZY_TOOL_PATCH, …
- (no CPE)
- osv-coords5 versionspkg:rpm/opensuse/gimp&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/gimp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/gimp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7pkg:rpm/suse/gimp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP6pkg:rpm/suse/gimp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7
< 2.10.30-150400.3.23.1+ 4 more
- (no CPE)range: < 2.10.30-150400.3.23.1
- (no CPE)range: < 2.10.30-150400.3.23.1
- (no CPE)range: < 2.10.30-150400.3.23.1
- (no CPE)range: < 2.10.30-150400.3.23.1
- (no CPE)range: < 2.10.30-150400.3.23.1
Patches
Vulnerability mechanics
References
4- access.redhat.com/security/cve/CVE-2025-6035nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- gitlab.gnome.org/GNOME/gimp/-/issues/13518nvd
- lists.debian.org/debian-lts-announce/2025/10/msg00022.htmlnvd
News mentions
0No linked articles in our index yet.