CyberRota
← Ana sayfaya dön

CVE-2026-66759

HIGH · CVSS 7.1 EPSS %0.13

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-27T19:17:23.747 · Çekilme zamanı: 2026-07-28T18:30:07.494766+00:00

CyberRota Yorumu

Bellek tüketimine neden olabilir.

CVE
CVE-2026-66759
Severity
HIGH
CVSS
7.1
EPSS
%0.13

Orijinal NVD Açıklaması

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed.