Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59090

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 8.4
EPSS Низкий

Описание

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the block_rem variable, occurs when a user opens a specially crafted .psd image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

Отчет

This is an Important severity flaw in the GIMP image manipulation program. An unsigned integer underflow in the PSD plugin can lead to arbitrary code execution when a user opens a specially crafted .psd file. This vulnerability primarily affects desktop environments where GIMP is installed and used to process untrusted image files.

Меры по смягчению последствий

To mitigate this vulnerability, users should avoid opening untrusted or suspicious PSD image files with GIMP. As a general security practice, it is recommended to only process image files from trusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpOut of support scope
Red Hat Enterprise Linux 7gimpAffected
Red Hat Enterprise Linux 8gimpAffected
Red Hat Enterprise Linux 9gimpAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2496584gimp: GIMP: Arbitrary code execution in PSD plugin due to unsigned underflow

EPSS

Процентиль: 24%
0.00308
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
ubuntu
17 дней назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

CVSS3: 8.4
nvd
17 дней назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

CVSS3: 8.4
debian
17 дней назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, ...

CVSS3: 8.4
github
17 дней назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

EPSS

Процентиль: 24%
0.00308
Низкий

8.4 High

CVSS3

Уязвимость CVE-2026-59090