Out-of-bounds Write Vulnerability in GIMP's GIMPressionist Plugin
CVE-2026-97185
7.8HIGH
What is CVE-2026-97185?
An identified flaw in GIMP occurs when processing a specifically crafted GIMPressionist preset file. The plug-in fails to validate vector indices correctly before writing to fixed-size arrays, which may result in out-of-bounds writes leading to memory corruption. Attackers can exploit this issue by persuading users to load malicious preset files, risking application crashes and the potential for arbitrary code execution.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Harsh Verma for reporting this issue.