CVE-2026-4887 Details
Description
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
A heap buffer over-read vulnerability has been identified in GIMP's PCX file loader, versions through 2.10.30 and 3.2.0-RC3+git. This vulnerability arises from an off-by-one error in the validation of the 'bytesperline' parameter, allowing remote attackers to craft PCX images that, when opened by the user, cause GIMP to read beyond the intended memory boundaries. This exploitation can lead to unauthorized memory disclosure and potentially cause the application to crash, creating a denial-of-service condition.
Users are advised to avoid opening untrusted PCX files with GIMP. If GIMP is not needed, consider uninstalling it to remove this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-193 | Off-by-one Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gimp gimp | < 3.2.0 3.2.0 rc1 3.2.0 rc2 3.2.0 rc3 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 14, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | New CVE Received | [email protected] |