No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this issue, avoid opening or processing untrusted APNG (Animated Portable Network Graphics) image files with GIMP. Since the vulnerability is triggered by malformed APNG content, restricting interaction with such files will prevent the `file-png` plugin from crashing. If the plugin crashes, restarting GIMP may be necessary to restore full functionality.
Mon, 03 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user. | |
| Title | Gimp: gimp file-png plugin: denial of service via oversized apng trns chunk | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-120 | |
| CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-03T04:05:27.175Z
Reserved: 2026-04-20T16:43:07.025Z
Link: CVE-2026-6694
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T09:00:15Z