CVE-2026-77652: Heap-based Buffer Overflow in GNOME Dia
Description
CVE-2026-77652 is a heap-based buffer overflow vulnerability in the Dia diagram editor's WPG file format importer. The flaw arises from improper bounds checking when reading palette data, allowing an attacker to overflow the palette buffer. Exploitation requires a user to open a crafted WPG file, potentially leading to application crashes or arbitrary code execution. No special privileges are needed to trigger the vulnerability. The issue affects all Dia versions containing the vulnerable code path as of August 2026. Red Hat has assessed that this vulnerability does not affect any currently supported Red Hat products.
CVSS v3.1
Score 7.8high
Affected software
GNOME
Dia
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in the WPG import renderer of Dia (plug-ins/wpg/wpg-import.c), where a fixed palette of 256 entries is allocated. When processing a WPG_COLORMAP record, the parser reads a start index (i16) and number of colors (iNum16) from the file and reads palette data into the allocated buffer without proper validation that i16 and i16 + iNum16 do not exceed the palette capacity of 256 entries. A malicious WPG file can specify i16=256 and iNum16=264, causing fread() to write 792 bytes beyond the allocated 768-byte buffer, overflowing into adjacent heap metadata. This can cause Dia to crash due to malloc corruption or, depending on heap layout and exploit conditions, allow arbitrary code execution. Exploitation requires user interaction to open a crafted WPG file. The vulnerability was confirmed in Dia 0.98+git20260221-1 and is present in upstream master as of 2026-08-21.
Potential Impact
The vulnerability can lead to denial of service through application crashes (SIGABRT or malloc corruption errors) and potentially arbitrary code execution if an attacker can control heap layout and exploit primitives. The impact includes full compromise of the affected application process, potentially affecting confidentiality, integrity, and availability. No special privileges are required for exploitation, but user interaction is necessary to open a malicious WPG file.
Mitigation Recommendations
Red Hat's advisory states that this vulnerability does not affect any currently supported Red Hat products. No official patch or fix is currently documented in the advisory. Users of Dia should monitor the upstream project for patches addressing this issue. Until a fix is available, avoid opening untrusted WPG files with Dia to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- fedora
- Date Reserved
- 2026-08-21T04:00:13.905Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-77652","vendor":"Red Hat"}]
Threat ID: 6a8f4092acd9273b494e80de
Added to database: 08/26/2026, 19:37:54 UTC
Last enriched: 09/09/2026, 15:52:46 UTC
Last updated: 10/10/2026, 18:48:22 UTC
Views: 91
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.