PT-2026-28660 · Gimp+2 · Gimp+2

CVE-2026-4887

·

Published

2026-01-01

·

Updated

2026-07-29

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description A heap buffer over-read exists in the PCX file loader due to an off-by-one error. A remote attacker can trigger this by inducing a user to open a specially crafted PCX image. This may result in out-of-bounds memory disclosure or an application crash, leading to a Denial of Service (DoS).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:16484
ALSA-2026:17533
ALSA-2026:19362
BDU:2026-13671
CVE-2026-4887
OESA-2026-1810
OESA-2026-1811
OESA-2026-1812
OESA-2026-1813
OESA-2026-2671
RHSA-2026:16484
RHSA-2026:17533
RHSA-2026:25899
RHSA-2026:25901
RHSA-2026:25907
SUSE-SU-2026:2756-1

Affected Products

Gimp
Red Os
Rocky Linux