Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4154

Опубликовано: 11 апр. 2026
Источник: redhat
CVSS3: 7.8

Описание

GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XPM files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28901.

A flaw was found in GIMP. Remote attackers can exploit this vulnerability by tricking a user into opening a malicious XPM (X PixMap) image file. This can lead to an an integer overflow during file processing, allowing the attacker to execute arbitrary code on the affected system.

Отчет

This is an Important vulnerability in GIMP that could lead to arbitrary code execution. Exploitation requires a user to open a specially crafted XPM image file. Red Hat Enterprise Linux systems with GIMP installed are affected if users process untrusted XPM files.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening XPM image files from untrusted sources. On systems where GIMP is not required, the gimp package can be removed. Removing desktop-related packages may impact graphical environment functionality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpOut of support scope
Red Hat Enterprise Linux 7 Extended Lifecycle SupportgimpFixedRHSA-2026:2616816.06.2026
Red Hat Enterprise Linux 8gimpFixedRHSA-2026:1753314.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgimpFixedRHSA-2026:2055226.05.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OngimpFixedRHSA-2026:2055226.05.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportgimpFixedRHSA-2026:2055326.05.2026
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicegimpFixedRHSA-2026:2055326.05.2026
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsgimpFixedRHSA-2026:2055326.05.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicegimpFixedRHSA-2026:2055426.05.2026
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsgimpFixedRHSA-2026:2055426.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2457530gimp: GIMP: Remote Code Execution via XPM File Parsing Integer Overflow

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XPM files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28901.

CVSS3: 7.8
nvd
4 месяца назад

GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XPM files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28901.

CVSS3: 7.8
debian
4 месяца назад

GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerabi ...

CVSS3: 7.8
github
4 месяца назад

GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XPM files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28901.

CVSS3: 7.8
fstec
5 месяцев назад

Уязвимость библиотеки для обработки изображений Gimp, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код

7.8 High

CVSS3

Уязвимость CVE-2026-4154