Description
A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
To mitigate this vulnerability, do not open SFW files from untrusted sources with GIMP.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 26 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service. | |
| Title | Gimp: stack vla size underflow denial of service in seattle | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-26T15:38:04.436Z
Reserved: 2026-08-25T14:50:35.232Z
Link: CVE-2026-79902
No data.
Status : Received
Published: 2026-08-26T14:17:16.430
Modified: 2026-08-26T14:17:16.430
Link: CVE-2026-79902
No data.
OpenCVE Enrichment
Updated: 2026-08-26T15:15:07Z
Weaknesses