CVE-2026-42170Disclosure(redhat / enterprise_linux)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's stride causes a write past the heap buffer boundary, leading to heap metadata corruption and potential code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-131

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_linux

4 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-08: 1Mentions · 2026-08-10: 1Patch / Workaround · 2026-08-10: 1Technical Details · 2026-08-08: 1Technical Details · 2026-08-10: 108-0808-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ThreatAft@ThreatAft
    Disclosure

    🔐 🚨 GIMP DDS Parser Heap Overflow — CVSS 7.8 CVE-2026-42170: Crafted DDS file → heap overflow → code execution. No official patch yet. Avoid untrusted DDS files. → http://threataft.com/articles/gimp-cve-2026-42170-dds-heap-overflow #cybersecurity #infosec #GIMP #Vulnerability #ThreatIntel

    Post summary

    The post announces a new GIMP DDS parser heap‑overflow vulnerability (CVE-2026-42170), details its technical impact, notes no patch is available, and advises users to avoid untrusted DDS files. No PoC, exploit, or active exploitation is claimed.

    0000062
    36 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🔥 New GIMP vulnerability can lead to memory corruption CVE-2026-42170 affects GIMP's DDS image parser. A specially crafted DDS image can trigger a heap-based buffer overflow, potentially causing memory corruption and possible code execution. 📊 CVSS: 7.8 High 📅 CVE published: August 8 🔎 Source: Red Hat / CVE / Vulners. #GIMP #CVE #MemorySafety #CyberSecurity

    Post summary

    The post announces the newly disclosed GIMP CVE‑2026‑42170, detailing a heap‑based buffer overflow that can lead to memory corruption and potential code execution, yet it does not provide a PoC, exploit code, or patch.

    0000045
    34 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more