Remote Code Execution Vulnerability in GIMP by GNOME
CVE-2025-14422

7.8HIGH

Key Information:

Vendor

Gimp

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-14422?

A significant vulnerability exists in GIMP's handling of PNM files, allowing remote attackers to execute arbitrary code. The flaw arises from inadequate validation of user-supplied data, leading to an integer overflow during buffer allocation. To exploit this vulnerability, an attacker must entice a user to visit a malicious webpage or open a crafted PNM file, triggering the vulnerability. This issue emphasizes the importance of secure coding practices and timely updates to safeguard against potential exploits.

Affected Version(s)

GIMP 3.0.6

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.