Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58379

Опубликовано: 11 апр. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.

Отчет

This is an Important severity flaw in GIMP's Paint Shop Pro (PSP) file format parser. A heap buffer overflow can occur when processing a specially crafted PSP file, potentially leading to arbitrary code execution or denial of service. Exploitation requires user interaction, as a malicious file must be opened by the GIMP application.

Меры по смягчению последствий

To mitigate this vulnerability, users should avoid opening untrusted Paint Shop Pro (PSP) image files with GIMP. As a general security practice, it is recommended to only process image files from trusted sources. If GIMP is not essential, consider removing the package to eliminate the attack surface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpNot affected
Red Hat Enterprise Linux 7gimpNot affected
Red Hat Enterprise Linux 8gimp:2.8/gimpNot affected
Red Hat Enterprise Linux 9gimpFixedRHSA-2026:3849613.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2495997gimp: gimp: Heap buffer overflow in read_channel_data()

EPSS

Процентиль: 14%
0.00233
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
28 дней назад

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.

CVSS3: 7.3
nvd
28 дней назад

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.

CVSS3: 7.3
debian
28 дней назад

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. Th ...

CVSS3: 7.3
github
28 дней назад

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.

oracle-oval
19 дней назад

ELSA-2026-38496: gimp security update (IMPORTANT)

EPSS

Процентиль: 14%
0.00233
Низкий

7.3 High

CVSS3

Уязвимость CVE-2026-58379