{"id":"CVE-2026-96546","published":"2026-09-23T19:19:54.373","lastModified":"2026-09-25T18:17:34.120","description":"A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.","cvssScore":2.5,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","cwes":["CWE-125"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-96546","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539601","tags":[]},{"url":"https://gitlab.gnome.org/GNOME/gimp/-/work_items/16802","tags":[]},{"url":"https://gitlab.gnome.org/GNOME/gimp/-/work_items/16802","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}