Memory Corruption Vulnerability in GIMP Lighting Effects
CVE-2026-90947

7.8HIGH

What is CVE-2026-90947?

A memory corruption vulnerability exists in GIMP's Lighting Effects filter, which fails to properly validate the number of light sources in specially crafted lighting preset files. This oversight can result in an out-of-bounds write, leading to memory corruption. An attacker could exploit this vulnerability by persuading a user to open a compromised preset file, which may result in application crashes or enable the execution of arbitrary code.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Harsh Verma for reporting this issue.
.