Heap-based Buffer Overflow in GIMP JP2 File Parsing
CVE-2026-4152
7.8HIGH
What is CVE-2026-4152?
A vulnerability exists in the GIMP application that affects its handling of JP2 files. An insufficient validation of user-supplied data length leads to a heap-based buffer overflow, allowing remote attackers to execute arbitrary code on the affected systems. This exploitation requires user interaction, necessitating the victim to open a malicious JP2 file or visit a harmful website. Awareness and prompt application of security updates are essential to mitigate this risk.
Affected Version(s)
GIMP 3.0.8
