Out-of-bounds Write Vulnerability in GIMP's GIMPressionist Plugin
CVE-2026-97185

7.8HIGH

What is CVE-2026-97185?

An identified flaw in GIMP occurs when processing a specifically crafted GIMPressionist preset file. The plug-in fails to validate vector indices correctly before writing to fixed-size arrays, which may result in out-of-bounds writes leading to memory corruption. Attackers can exploit this issue by persuading users to load malicious preset files, risking application crashes and the potential for arbitrary code execution.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Harsh Verma for reporting this issue.
.