Unsigned Integer Underflow in GIMP PSD Plugin
CVE-2026-59090
8.4HIGH
What is CVE-2026-59090?
A vulnerability exists within GIMP's PSD file format plugin that stems from an unsigned integer underflow in the block_rem variable. When a user opens a specially crafted .psd image file, the underflow can cause confusion in the parser. This confusion can allow an attacker to inject arbitrary data into layer resource blocks, ultimately resulting in the possibility of executing malicious code on the victim's system. This poses significant risks to users who handle potentially harmful PSD files.