Heap-Based Buffer Overflow in GIMP's PSP File Loader
CVE-2026-90949
7.8HIGH
What is CVE-2026-90949?
A vulnerability in GIMP's Paint Shop Pro (PSP) file loader allows for a heap-based buffer overflow during the processing of a compressed selection channel. This flaw stems from an improper match between the allocated buffer size and the size of the decompressed data. An attacker can exploit this vulnerability by creating a malicious PSP file, and if opened in GIMP, it may result in application crashes or arbitrary code execution.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank hoyong jin for reporting this issue.