Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40916

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-length array.

Отчет

This flaw has a Moderate impact. This vulnerability in GIMP's TIM image loader requires a local user to open a specially crafted TIM image file, leading to a denial of service. Red Hat Enterprise Linux systems are affected if GIMP is installed and used to process untrusted image files.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening untrusted TIM image files with GIMP. As a general security practice, users should exercise caution when handling files from unknown or suspicious sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpFix deferred
Red Hat Enterprise Linux 7gimpFix deferred
Red Hat Enterprise Linux 8gimp:2.8/gimpFix deferred
Red Hat Enterprise Linux 9gimpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2458745gimp: GIMP: Denial of Service due to stack buffer overflow in TIM image loader

EPSS

Процентиль: 11%
0.0021
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
4 месяца назад

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-length array.

CVSS3: 5
nvd
4 месяца назад

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-length array.

CVSS3: 5
debian
4 месяца назад

A flaw was found in GIMP. A stack buffer overflow vulnerability in the ...

CVSS3: 5
github
4 месяца назад

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-length array.

CVSS3: 5
fstec
4 месяца назад

Уязвимость загрузчика изображений TIM библиотеки для обработки изображений Gimp, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 11%
0.0021
Низкий

5 Medium

CVSS3