Skip to main content
EPSS 0.2%top 89%

CVE-2026-77652: Heap-based Buffer Overflow in GNOME Dia

0
High
VulnerabilityCVE-2026-77652cvecve-2026-77652
Published: 08/26/2026 (08/26/2026, 19:21:39 UTC)
Source: CVE Database V5
Vendor/Project: GNOME
Product: Dia

Description

CVE-2026-77652 is a heap-based buffer overflow vulnerability in the Dia diagram editor's WPG file format importer. The flaw arises from improper bounds checking when reading palette data, allowing an attacker to overflow the palette buffer. Exploitation requires a user to open a crafted WPG file, potentially leading to application crashes or arbitrary code execution. No special privileges are needed to trigger the vulnerability. The issue affects all Dia versions containing the vulnerable code path as of August 2026. Red Hat has assessed that this vulnerability does not affect any currently supported Red Hat products.

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

GNOME

Dia

Affected versions
>=0 <=0.98+git20260221-1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/09/2026, 15:52:46 UTC

Technical Analysis

The vulnerability exists in the WPG import renderer of Dia (plug-ins/wpg/wpg-import.c), where a fixed palette of 256 entries is allocated. When processing a WPG_COLORMAP record, the parser reads a start index (i16) and number of colors (iNum16) from the file and reads palette data into the allocated buffer without proper validation that i16 and i16 + iNum16 do not exceed the palette capacity of 256 entries. A malicious WPG file can specify i16=256 and iNum16=264, causing fread() to write 792 bytes beyond the allocated 768-byte buffer, overflowing into adjacent heap metadata. This can cause Dia to crash due to malloc corruption or, depending on heap layout and exploit conditions, allow arbitrary code execution. Exploitation requires user interaction to open a crafted WPG file. The vulnerability was confirmed in Dia 0.98+git20260221-1 and is present in upstream master as of 2026-08-21.

Potential Impact

The vulnerability can lead to denial of service through application crashes (SIGABRT or malloc corruption errors) and potentially arbitrary code execution if an attacker can control heap layout and exploit primitives. The impact includes full compromise of the affected application process, potentially affecting confidentiality, integrity, and availability. No special privileges are required for exploitation, but user interaction is necessary to open a malicious WPG file.

Mitigation Recommendations

Red Hat's advisory states that this vulnerability does not affect any currently supported Red Hat products. No official patch or fix is currently documented in the advisory. Users of Dia should monitor the upstream project for patches addressing this issue. Until a fix is available, avoid opening untrusted WPG files with Dia to mitigate risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
fedora
Date Reserved
2026-08-21T04:00:13.905Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-77652","vendor":"Red Hat"}]

Threat ID: 6a8f4092acd9273b494e80de

Added to database: 08/26/2026, 19:37:54 UTC

Last enriched: 09/09/2026, 15:52:46 UTC

Last updated: 10/10/2026, 18:48:22 UTC

Views: 91

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses