#1146702 dia: CVE-2026-77652

Package:
src:dia
Source:
src:dia
Submitter:
Moritz Mühlenhoff
Date:
2026-09-04 17:39:02 UTC
Severity:
normal
Tags:
#1146702#5
Date:
2026-09-04 16:07:39 UTC
From:
To:
Hi,

The following vulnerability was published for dia.

CVE-2026-77652[0]:
| A heap-based buffer overflow vulnerability exists in the Dia diagram
| editor WPG file format importer.  In plug-ins/wpg/wpg-import.c, the
| WPG import renderer allocates a fixed palette with:      ren->pPal =
| g_new0(WPGColorRGB, 256);  When handling a WPG_COLORMAP record, the
| parser reads a start index (i16) and number of colors (iNum16) from
| the file and reads palette data with:      bRet &= (iNum16 ==
| (int)fread(&ren->pPal[i16], sizeof(WPGColorRGB), iNum16, f));  The
| only bounds-related check is `if (i16 >= 0 && i16 <= iSize)`, where
| iSize is the WPG record size—not the palette capacity. There is no
| validation that i16 is less than 256 or that i16 + iNum16 does not
| exceed 256.  A malicious WPG file can supply i16=256 and iNum16=264.
| That causes fread() to write 792 bytes starting at &pPal[256], while
| the palette buffer is only 768 bytes (256 entries × 3 bytes). This
| overflows into adjacent heap metadata and can crash Dia (SIGABRT /
| malloc corruption errors) or, depending on heap layout and exploit
| primitives, potentially lead to arbitrary code execution.
| Exploitation requires convincing a user to open a crafted WPG file
| via Dia's file dialog, command line, or file association. No special
| privileges are required to deliver the file to the victim.  Affected
| component: WPG parser (plug-ins/wpg/wpg-import.c). Affected
| versions: all Dia versions containing this code path (reporter
| tested Dia 0.98+git20260221-1; issue present on upstream master as
| of 2026-08-21).

https://gitlab.gnome.org/GNOME/dia/-/issues/580


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-77652
https://www.cve.org/CVERecord?id=CVE-2026-77652

Please adjust the affected versions in the BTS as needed.