Medium severity5.5NVD Advisory· Published Aug 26, 2026· Updated Sep 1, 2026
CVE-2026-79902
CVE-2026-79902
Description
A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2026-79902nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdPermissions Required
News mentions
1- GIMP: Four Image Plugin Vulnerabilities Disclosed, Ranging Medium to High SeverityVypr Intelligence · Aug 26, 2026