Vulnerabilities & PatchesEmerging1 src
CVE-2026-78475 - Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader
CVE ID : CVE-2026-78475
Published : Aug. 24, 2026, 6:17 p. m.
• 54 minutes ago
Description : A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read.
This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.
Severity: 6.1
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...