SEPTEMBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-82330

MEDIUM · CVSS 6.1 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The file-pvr plugin in GIMP is vulnerable due to inadequate memory bounds checking when processing specially crafted PVR image files, leading to a heap out-of-bounds read. This flaw can cause application crashes, resulting in denial of service and potential exposure of sensitive heap memory contents. Users and administrators of GIMP should prioritize addressing this vulnerability to mitigate risks associated with application stability and data security.

CVE
CVE-2026-82330
Severity
MEDIUM
CVSS
6.1
EPSS
0.12%

Original NVD Description

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Related CVEs

Other vulnerabilities affecting the same vendor(s)