Heap-based Buffer Overflow in GIMP by GNOME
CVE-2026-4153
7.8HIGH
What is CVE-2026-4153?
A vulnerability in GIMP allows attackers to execute arbitrary code by exploiting a flaw in the parsing process of PSP files. This occurs due to inadequate validation of user-supplied data length before storage in a heap-based buffer. Successful exploitation requires user interaction, as the target must either access a malicious website or open a compromised file. By leveraging this vulnerability, an attacker can execute arbitrary code within the context of the affected process, posing a significant security risk for users.
Affected Version(s)
GIMP 3.0.8
