CVE-2026-79902

Summary

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.

Affected Software

VendorProductVersion RangeStatus
GNOMEGIMP3.1.4 < *affected

Weaknesses

  • CWE-190: Integer Overflow or Wraparound

Workarounds

To mitigate this vulnerability, do not open SFW files from untrusted sources with GIMP.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References