CVE-2026-2047
7.8GIMP · GIMP
A heap-based buffer overflow vulnerability in GIMP allows remote attackers to execute arbitrary code via a malicious ICNS file.
Executive summary
A heap-based buffer overflow in GIMP version 3.0.6 allows for remote code execution when a user opens a maliciously crafted ICNS image file.
Vulnerability
The vulnerability exists due to improper validation of user-supplied data length during the parsing of ICNS files, leading to a heap-based buffer overflow. An attacker can trigger this condition if a victim opens a crafted file, allowing for execution of arbitrary code in the context of the user process.
Business impact
The potential for remote code execution poses a severe risk to organizational security, as it allows attackers to gain unauthorized control over individual workstations. Given the CVSS score of 7.8, this vulnerability is classified as High severity, indicating a significant threat to system integrity and data confidentiality if targeted users are compromised.
Remediation
Immediate Action: Update GIMP to the latest version provided by the vendor to incorporate the necessary length validation fixes.
Proactive Monitoring: Review file system access logs and monitor for unexpected process execution originating from image processing applications.
Compensating Controls: Implement endpoint protection solutions that scan incoming files for anomalies and restrict the execution of untrusted software or unauthorized file types.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a high risk to end-user systems. Organizations should prioritize patching GIMP installations to the latest available version and advise users to exercise caution when opening image files from untrusted or unknown sources. Immediate remediation is required to eliminate the risk of arbitrary code execution.
More GIMP CVEs
Sources
- ZDI-26-120
- vendor-provided URL Vendor advisory