No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this avoid exporting untrusted or unnecessarily huge images to DICOM; cap image dimensions in workflows that process third-party content. Use checked multiplication and maximum dimension limits in custom automation that drives GIMP export.
Tue, 06 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export path allocates a buffer using a 32-bit width * height (and bytes-per-pixel) product that can overflow. GEGL then writes the full uncompressed extent into the undersized buffer (CWE-787), after integer overflow in the allocation size | |
| Title | Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-119 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-06T19:34:29.710Z
Reserved: 2026-10-06T14:27:03.614Z
Link: CVE-2026-106063
No data.
Status : Received
Published: 2026-10-06T20:17:17.090
Modified: 2026-10-06T20:17:17.090
Link: CVE-2026-106063
No data.
OpenCVE Enrichment
Updated: 2026-10-06T21:00:06Z