Medium severity5.5NVD Advisory· Published Jul 27, 2026· Updated Aug 10, 2026
CVE-2026-66757
CVE-2026-66757
Description
A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This integer overflow issue results in undefined behavior, aborting the plugin and causing a denial of service.
Affected products
7cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- osv-coords2 versionspkg:rpm/opensuse/gimp&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/gimp&distro=openSUSE%20Tumbleweed
< 3.0.8-bp160.6.1+ 1 more
- (no CPE)range: < 3.0.8-bp160.6.1
- (no CPE)range: < 3.2.4-3.1
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2026-66757nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
1- GIMP: Three File Plugin Vulnerabilities Disclosed Together on July 28, 2026Vypr Intelligence · Jul 28, 2026