CVE-2026-106062: Improper Restriction of Operations within the Bounds of a Memory Buffer in Red Hat Red Hat Enterprise Linux 10
Description
CVE-2026-106062 is a heap-based buffer overflow vulnerability in GIMP's DirectDraw Surface (DDS) loader on Red Hat Enterprise Linux 10. The issue arises from integer overflow during buffer size calculations, leading to insufficient buffer allocation and potential heap corruption. This flaw can be exploited to achieve arbitrary code execution within the GIMP process context. The vulnerability has a high severity rating with a CVSS score of 7.8.
CVSS v3.1
Score 7.8high
Affected software
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 6
Red Hat
Red Hat Enterprise Linux 7
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 9
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper restriction of operations within the bounds of a memory buffer in GIMP's DDS loader. Specifically, when loading a crafted DDS image, buffer sizes derived from width, height, and pitch are calculated using 32-bit arithmetic that can overflow. This causes the allocated buffer to be smaller than required for the pixel data written through GEGL, resulting in heap corruption and potentially arbitrary code execution. The vulnerability is tracked as CVE-2026-106062 and affects Red Hat Enterprise Linux 10.
Potential Impact
Successful exploitation can lead to heap corruption and arbitrary code execution within the GIMP process. This can compromise the confidentiality, integrity, and availability of the affected system. The CVSS v3.1 score of 7.8 reflects high impact on confidentiality, integrity, and availability with low attack complexity and no privileges required but user interaction needed.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-106062 for current remediation guidance. Until a patch is available, avoid opening untrusted DDS images with GIMP to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-10-06T14:26:58.730Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-106062","vendor":"Red Hat"}]
Threat ID: 6ac55b392cdf04f656dc289f
Added to database: 10/06/2026, 20:34:01 UTC
Last enriched: 10/06/2026, 20:48:18 UTC
Last updated: 10/06/2026, 20:49:08 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.