PT-2026-69481 · Gimp · Gimp

CVE-2026-59090

·

Published

2026-08-10

·

Updated

2026-08-31

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description A flaw exists in the PSD file format plugin where an unsigned integer underflow occurs in the block rem variable when opening a specially crafted .psd image file. This underflow causes parser confusion, allowing an attacker to inject arbitrary data as layer resource blocks, which can lead to arbitrary code execution on the victim's system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61587
CVE-2026-59090
OESA-2026-3573
OPENSUSE-SU-2026:11547-1
SUSE-SU-2026:3688-1

Affected Products

Gimp