What is CVE-2026-42170?
A heap-based buffer overflow vulnerability (CVE-2026-42170) has been discovered in GIMP's DDS file parser. Maliciously crafted D3D9 pixel format DDS files with inconsistent bits-per-pixel headers can trigger arbitrary code execution. Users are advised to update GIMP to the latest patched version and avoid opening untrusted DDS files.
Azərbaycanca: GIMP proqramının DDS fayl parserində heap-based buffer overflow zəifliyi (CVE-2026-42170) aşkarlanıb. Xüsusi hazırlanmış D3D9 formatlı DDS faylları vasitəsilə zərərli kod icrası mümkündür. İstifadəçilərə GIMP-i ən son versiyaya yeniləmək və şübhəli DDS fayllarından qaçınmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
What type of file can be used to exploit CVE-2026-42170?
Maliciously crafted DDS files with a D3D9 pixel format and inconsistent bits-per-pixel headers can be used to trigger arbitrary code execution through this vulnerability.
What is recommended to protect against CVE-2026-42170?
Users are advised to update GIMP to the latest patched version and avoid opening untrusted DDS files from suspicious sources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.