PT-2026-91216 · Gimp · Gimp

CVE-2026-90949

·

Published

2026-09-14

·

Updated

2026-10-01

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description A flaw exists in the PSP (Paint Shop Pro) file loader. A heap-based buffer overflow occurs when processing a compressed selection channel because the allocated buffer size does not match the amount of decompressed data. A remote attacker can exploit this by providing a specially crafted PSP file, which may result in a crash or arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90949
OPENSUSE-SU-2026:11890-1

Affected Products

Gimp