MEDIUM 5.5 NVD
CVE-2026-79902
A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA)
A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.
References
- https://access.redhat.com/security/cve/CVE-2026-79902
- https://bugzilla.redhat.com/show_bug.cgi?id=2523512
- https://gitlab.gnome.org/GNOME/gimp/-/work_items/16582
- https://gitlab.gnome.org/GNOME/gimp/-/work_items/16582
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-08-26 via NVD.
vulnfeed aggregates 11364 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.