CVE-2026-96543 is an out-of-bounds heap write vulnerability in GIMP's PVR image loader. When GIMP loads a crafted non-square PVR texture, the pvr_decode_twiddle() function does not bounds-check its destination offset and can write attacker-controlled pixel data past the end of a correctly allocated heap buffer.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical, network-accessible vulnerability identified as CVE-2026-96543, with CVSS v3 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The notice identifies Ubuntu Linux LTS releases 16.04 through 26.04 and GIMP as relevant CPE/package entries, but does not describe the underlying flaw or affected component in detail.
An important-severity out-of-bounds heap write in GIMP's PVR image loader. A malicious non-square PVR image can cause attacker-controlled pixel data to be written beyond an allocated heap buffer, potentially enabling arbitrary code execution in the file-pvr plug-in process when a user opens the file.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.