Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40918

Опубликовано: 15 апр. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PVR image files are affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gimpfixed3.2.2-1package
gimpnot-affectedtrixiepackage
gimpnot-affectedbookwormpackage
gimpnot-affectedbullseyepackage

Примечания

  • https://gitlab.gnome.org/GNOME/gimp/-/issues/16058

  • Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/7612363d8cdc574d482433a3897a24612bee4d81 (GIMP_3_2_2)

  • Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/96a9000169a11742cad88b6f945c12766cbf3f42 (GIMP_3_2_0)

EPSS

Процентиль: 10%
0.00196
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PVR image files are affected.

CVSS3: 5.5
redhat
4 месяца назад

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PVR image files are affected.

CVSS3: 5.5
nvd
4 месяца назад

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PVR image files are affected.

CVSS3: 5.5
github
4 месяца назад

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PVR image files are affected.

CVSS3: 5.5
fstec
4 месяца назад

Уязвимость библиотеки для обработки изображений Gimp, связанная с некорректными вычислениями размера выделяемого буфера, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 10%
0.00196
Низкий