Integer Overflow Vulnerability in GIMP Affecting TIF File Parsing
CVE-2026-18308

7.8HIGH

Key Information:

Vendor

Gimp

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-18308?

This vulnerability affects GIMP's handling of TIF file parsing and could allow remote attackers to execute arbitrary code on compromised installations. The flaw arises due to inadequate validation of user-supplied data during file processing. When a malicious TIF file is opened, it can trigger an integer overflow, leading to potentially exploitable conditions in the application's memory. To be vulnerable, the user must engage with the malicious file, thereby opening avenues for remote code execution under the context of the current user.

Affected Version(s)

GIMP 3.2.2

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.