PT-2026-91215 · Gimp+1 · Gimp+1
CVE-2026-90948
·
Published
2026-09-14
·
Updated
2026-10-01
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GIMP (affected versions not specified)
Red Hat Enterprise Linux (affected versions not specified)
Description
A flaw exists in the ICO file loader. When processing an ICO file that contains an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This results in the allocation of an undersized buffer, leading to a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by providing a specially crafted ICO file, which may result in a crash or arbitrary code execution.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gimp
Red Hat