Null Pointer Dereference Vulnerability in GIMP Image Processing Software
CVE-2026-108093
5.5MEDIUM
What is CVE-2026-108093?
A flaw in the GIMP image processing software allows for a potentially harmful interaction when opening specially crafted XCF files. The XCF loader inadequately checks for the presence of necessary parasite data before dereferencing, which can lead to a NULL pointer dereference. This vulnerability can cause the application to crash, disrupting user activities and potentially leading to data loss. Users are advised to be cautious when handling XCF files from untrusted sources.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Alexey Khairov (codem4ster), Konstantin Talgarenko (Marcusov), and Nikolay Kravtsov (Kolya080808) for reporting this issue.