Unsigned Integer Underflow in GIMP PSD Plugin
CVE-2026-59090

8.4HIGH

What is CVE-2026-59090?

A vulnerability exists within GIMP's PSD file format plugin that stems from an unsigned integer underflow in the block_rem variable. When a user opens a specially crafted .psd image file, the underflow can cause confusion in the parser. This confusion can allow an attacker to inject arbitrary data into layer resource blocks, ultimately resulting in the possibility of executing malicious code on the victim's system. This poses significant risks to users who handle potentially harmful PSD files.

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.