CVE-2026-4153
7.8GIMP · GIMP
A heap-based buffer overflow in GIMP allows remote attackers to execute arbitrary code by enticing a user to open a specially crafted PSP file.
Executive summary
A critical heap-based buffer overflow in GIMP 3.0.8 could allow a remote attacker to achieve arbitrary code execution on a victim system through a malicious PSP file.
Vulnerability
This vulnerability is a heap-based buffer overflow (CWE-122) occurring during the parsing of PSP files due to insufficient length validation of user-supplied data. The attack requires user interaction, as the victim must open a malicious file, and the attacker operates with the privileges of the user running the application.
Business impact
The ability for an attacker to execute arbitrary code on a host system poses a severe risk to organizational data integrity and confidentiality. Given the CVSS score of 7.8, this vulnerability is classified as High severity. Successful exploitation could lead to full system compromise, unauthorized data access, or the deployment of secondary malicious payloads within the internal network.
Remediation
Immediate Action: Update GIMP to a version containing the fix implemented in commit 98cb1371fd4e22cca75017ea3252dc32fc218712.
Proactive Monitoring: Monitor endpoint activity for unusual child processes spawned by the GIMP application or unexpected network connections originating from graphical editing workstations.
Compensating Controls: Implement file integrity monitoring and endpoint detection and response (EDR) solutions to identify and block the execution of files from untrusted sources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The risk of remote code execution via file parsing makes this a high-priority update for all environments where GIMP is installed. Users should avoid opening PSP files from untrusted or unknown sources until the software has been updated to the patched version. Security teams must ensure that all workstations running GIMP are included in the next patch cycle to mitigate the risk of exploitation.
More GIMP CVEs
Sources
- ZDI-26-220
- vendor-provided URL Vendor advisory