PT-2026-69481 · Gimp · Gimp
CVE-2026-59090
·
Published
2026-08-10
·
Updated
2026-08-31
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GIMP (affected versions not specified)
Description
A flaw exists in the PSD file format plugin where an unsigned integer underflow occurs in the
block rem variable when opening a specially crafted .psd image file. This underflow causes parser confusion, allowing an attacker to inject arbitrary data as layer resource blocks, which can lead to arbitrary code execution on the victim's system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gimp