PT-2026-55578 · Gimp · Gimp

·

CVE-2026-58379

·

Published

2026-07-03

·

Updated

2026-07-29

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description A heap buffer overflow exists in the Paint Shop Pro (PSP) file format parser. The issue occurs when the software incorrectly calculates buffer sizes while processing low bit-depth images, which leads to the overwriting of adjacent memory. A remote attacker can exploit this by tricking a user into opening a specially crafted PSP image file, potentially resulting in arbitrary code execution or a denial of service (DoS).
Recommendations Update GIMP to the patched build provided by your distribution.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:38496
CVE-2026-58379
OESA-2026-3095
OESA-2026-3096
OESA-2026-3097
OPENSUSE-SU-2026:11264-1
OPENSUSE-SU-2026:21359-1
RHSA-2026:38496
SUSE-SU-2026:3399-1

Affected Products

Gimp