What is CVE-2026-66758?
This vulnerability exists in GIMP's file-fits plugin, where processing a crafted FITS image file leads to an integer overflow in memory allocation size calculations using signed 32-bit integers for width and height. This can result in undersized memory allocation and potential arbitrary code execution. Updating GIMP to the latest version is recommended.
Azərbaycanca: Bu boşluq GIMP-in file-fits pluginində aşkarlanıb, işlənmiş FITS şəkil faylında width və height dəyərlərinin signed 32-bit integer hesablanması nəticəsində overflow baş verir və yaddaş ayrılması az olur. Təsirə məruz qalan sistemlərdə zərərli fayl vasitəsilə arbitrari kod icrası mümkün ola bilər. GIMP-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190; shared vendor: GIMP
FAQ2
In which GIMP plugin was CVE-2026-66758 discovered?
This vulnerability was discovered in GIMP's file-fits plugin.
How can users protect themselves against CVE-2026-66758?
Updating GIMP to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.