← All Advisories

CVE-2026-42169

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-42169

Key Details

CVECVE-2026-42169
CVSS Score / Version7.3 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Enterprise Linux, Red Hat Enterprise Linux Extended Update Support (EUS), Red Hat Enterprise Linux 9, and Red Hat Enterprise Linux 9.6 Extended Update Support
Classified asCWE-131 (Incorrect Calculation of Buffer Size)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatEnterprise Linux Extended Update Support (EUS)
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-42169
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-42169
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-42169