What is CVE-2026-42169?
A critical heap-buffer-overflow vulnerability has been discovered in GIMP's APNG file loader. When the `fcTL` width exceeds the `IHDR` width, pixel data is written past the allocated heap buffer, potentially leading to arbitrary code execution. Users should immediately update GIMP to the latest version and avoid opening untrusted APNG files.
Azərbaycanca: GIMP-in APNG fayl yükləyicisində kritik heap-buffer-overflow zəifliyi aşkar edilib. `fcTL` eni `IHDR` enini aşdıqda heap sahəsində yaddaş pozuntusu baş verir ki, bu da ixtiyari kod icrasına səbəb ola bilər. İstifadəçilər dərhal GIMP-i ən son versiyaya yeniləməli və şübhəli APNG faylları açmamalıdır.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Under what condition is the CVE-2026-42169 vulnerability triggered in GIMP?
The vulnerability is triggered when the `fcTL` width of an APNG file exceeds the `IHDR` width, causing a heap-buffer-overflow where pixel data is written past the allocated heap buffer.
What measures are recommended to protect against CVE-2026-42169?
Users are recommended to immediately update GIMP to the latest version and avoid opening untrusted APNG files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.