Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40915

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data. Successful exploitation could result in a denial of service (DoS) or potentially arbitrary code execution.

Отчет

Moderate. This flaw in GIMP's FITS image loader could lead to a denial of service or arbitrary code execution when processing a specially crafted FITS file. Exploitation requires user interaction, as a malicious file must be opened by the application. Red Hat Enterprise Linux systems are affected if GIMP is installed and used to open untrusted FITS image files.

Меры по смягчению последствий

Users should avoid opening untrusted FITS image files with GIMP. If GIMP is not required, consider removing the gimp package to eliminate the attack surface. This can be done using the system's package manager, for example: sudo dnf remove gimp. Removing GIMP may impact other applications that depend on it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpFix deferred
Red Hat Enterprise Linux 7gimpFix deferred
Red Hat Enterprise Linux 8gimp:2.8/gimpFix deferred
Red Hat Enterprise Linux 9gimpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2458744gimp: GIMP: Heap buffer overflow due to integer overflow in FITS image loader

EPSS

Процентиль: 30%
0.00375
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data. Successful exploitation could result in a denial of service (DoS) or potentially arbitrary code execution.

CVSS3: 5.5
nvd
4 месяца назад

A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data. Successful exploitation could result in a denial of service (DoS) or potentially arbitrary code execution.

CVSS3: 5.5
debian
4 месяца назад

A flaw was found in GIMP. A remote attacker could exploit an integer o ...

CVSS3: 5.5
github
4 месяца назад

A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data. Successful exploitation could result in a denial of service (DoS) or potentially arbitrary code execution.

CVSS3: 5.5
fstec
4 месяца назад

Уязвимость библиотеки для обработки изображений Gimp, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 30%
0.00375
Низкий

5.5 Medium

CVSS3