CVE-2026-6694

MEDIUM CVSS 3.1: 5.5 EPSS 0.15%
Updated Aug 03, 2026
Red Hat
Parameter Value
CVSS 5.5 (MEDIUM)
Type CWE-120 (Buffer Copy without Checking Size)
Vendor Red Hat
Public PoC No

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products

red hat:red hat enterprise linux 7 red hat:red hat enterprise linux 9 red hat:red hat enterprise linux 6 red hat:red hat enterprise linux 8