Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58384

Опубликовано: 11 апр. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

Отчет

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can make the RLE row-length allocation too small and lead to heap memory corruption during subsequent row processing. Successful exploitation requires a user to open a specially crafted PSD file.

Меры по смягчению последствий

None — requires opening a crafted PSD file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpNot affected
Red Hat Enterprise Linux 7gimpNot affected
Red Hat Enterprise Linux 8gimp:2.8/gimpNot affected
Red Hat Enterprise Linux 9gimpFixedRHSA-2026:4075116.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2497431gimp: gimp: Integer overflow in read_RLE_channel()

EPSS

Процентиль: 17%
0.00257
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
25 дней назад

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
nvd
25 дней назад

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVSS3: 7.3
debian
25 дней назад

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE ...

CVSS3: 7.3
github
25 дней назад

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

oracle-oval
16 дней назад

ELSA-2026-40751: gimp security update (IMPORTANT)

EPSS

Процентиль: 17%
0.00257
Низкий

7.3 High

CVSS3