Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58382

Опубликовано: 11 апр. 2026
Источник: redhat
CVSS3: 7.3

Описание

A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap-based out-of-bounds write occurs in the ReadJeffsImage() function when a crafted JIF file supplies an invalid bits-per-pixel value that causes the unpack loop to write beyond the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

Отчет

A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap out-of-bounds write in the ReadJeffsImage() function can lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Successful exploitation requires a user to open a specially crafted JIF file with a build that includes the JIF import path.

Меры по смягчению последствий

None — requires opening a crafted JIF/GIF file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpNot affected
Red Hat Enterprise Linux 7gimpNot affected
Red Hat Enterprise Linux 8gimp:2.8/gimpNot affected
Red Hat Enterprise Linux 9gimpNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2497384gimp: gimp: Heap buffer overflow write in ReadJeffsImage()

7.3 High

CVSS3

Связанные уязвимости

ubuntu
26 дней назад

[Unknown description]

debian

Описание отсутствует

7.3 High

CVSS3