Heap-Based Buffer Overflow in GIMP's PSP File Loader
CVE-2026-90949

7.8HIGH

What is CVE-2026-90949?

A vulnerability in GIMP's Paint Shop Pro (PSP) file loader allows for a heap-based buffer overflow during the processing of a compressed selection channel. This flaw stems from an improper match between the allocated buffer size and the size of the decompressed data. An attacker can exploit this vulnerability by creating a malicious PSP file, and if opened in GIMP, it may result in application crashes or arbitrary code execution.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank hoyong jin for reporting this issue.
.