Remote Code Execution Vulnerability in GIMP by GNOME
CVE-2026-18300
7.8HIGH
What is CVE-2026-18300?
A vulnerability exists in GIMP's HDR file parsing that enables remote code execution due to improper validation of user-input data. This flaw could allow an attacker to exploit the vulnerability by convincing a user to open a malicious HDR file, triggering an integer overflow prior to buffer allocation. Consequently, this could lead to execution of arbitrary code within the context of the currently running process. For more details, refer to the official advisory and the vendor's detailed resolution commit.
Affected Version(s)
GIMP 3.2.2
