Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58381

Опубликовано: 11 апр. 2026
Источник: redhat
CVSS3: 6.1

Описание

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.

Отчет

This flaw is rated as Moderate. A double-free vulnerability within GIMP's Paint Shop Pro (PSP) file format parser can lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Successful exploitation requires a local attacker to persuade a user to open a specially crafted PSP file using GIMP.

Меры по смягчению последствий

None — requires opening a crafted PSP file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpOut of support scope
Red Hat Enterprise Linux 7gimpFix deferred
Red Hat Enterprise Linux 8gimp:2.8/gimpFix deferred
Red Hat Enterprise Linux 9gimpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-415
https://bugzilla.redhat.com/show_bug.cgi?id=2496166gimp: gimp: Double-free in read_layer_block()

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 1 месяца назад

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.

CVSS3: 6.1
nvd
около 1 месяца назад

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.

CVSS3: 6.1
debian
около 1 месяца назад

A flaw was found in GIMP's PSP file format parser. A double-free condi ...

CVSS3: 6.1
github
около 1 месяца назад

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.

suse-cvrf
20 дней назад

Security update for gimp

6.1 Medium

CVSS3