PT-2026-91215 · Gimp+1 · Gimp+1

CVE-2026-90948

·

Published

2026-09-14

·

Updated

2026-10-01

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified) Red Hat Enterprise Linux (affected versions not specified)
Description A flaw exists in the ICO file loader. When processing an ICO file that contains an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This results in the allocation of an undersized buffer, leading to a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by providing a specially crafted ICO file, which may result in a crash or arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90948
OPENSUSE-SU-2026:11890-1
OPENSUSE-SU-2026:21959-1
SUSE-SU-2026:4409-1

Affected Products

Gimp
Red Hat