What is CVE-2026-66759?
A vulnerability in GIMP's file-icns plugin can cause a buffer overflow when processing a crafted ICNS file with a truncated mask resource. This could allow remote code execution, so users are advised to update GIMP to the latest patched version.
Azərbaycanca: GIMP-in file-icns plaginində boşluq aşkarlanıb. Xüsusi hazırlanmış ICNS faylı emal edilərkən, dekompressiya olunmuş mask buferində sərhəd yoxlanışı olmadığı üçün bufer daşması (buffer overflow) baş verə bilər. Bu zəiflikdən istifadə edərək uzaqdan kod icrası mümkündür, ona görə də istifadəçilərə GIMP-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ1
How can the CVE-2026-66759 vulnerability in GIMP be exploited?
An attacker can craft a malicious ICNS file that triggers a buffer overflow in the decompressed mask buffer of GIMP's file-icns plugin, leading to potential remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.