CVE-2026-66759 Details
Description
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed.
A heap out-of-bounds read vulnerability has been identified in the file-icns plugin of GIMP, affecting versions 2.99.14 and newer. The issue arises when the plugin processes ICNS images with decompressed masks. The plugin fails to verify if the read cursor exceeds the allocated buffer size, allowing crafted files with truncated mask resources to be exploited. This vulnerability can lead to information disclosure, with leaked memory contents appearing as alpha channel pixel values, or cause a crash by accessing unmapped memory, resulting in a denial-of-service condition.
Users are advised not to open ICNS files from untrusted sources with GIMP.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.gnome.org/GNOME/gimp/-/issues/16528 | CISA-ADP | ExploitIssue TrackingVendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:50817 | [email protected] | Issue Tracking |
| https://access.redhat.com/security/cve/CVE-2026-66759 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2507557 | [email protected] | Issue TrackingVendor Advisory |
| https://gitlab.gnome.org/GNOME/gimp/-/issues/16528 | [email protected] | ExploitIssue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gimp gimp | 3.0.8 3.2.4 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 24, 2026 | CVE Modified | [email protected] |
| Aug 7, 2026 | Initial Analysis | [email protected] |
| Aug 5, 2026 | CVE Modified | [email protected] |
| Aug 3, 2026 | CVE Modified | [email protected] |
| Jul 31, 2026 | CVE Modified | [email protected] |
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | [email protected] |