CVE-2026-59090

8.4

Red Hat · Red Hat Enterprise Linux (GIMP PSD plugin)

An integer underflow vulnerability exists in the GIMP PSD file format plugin within Red Hat Enterprise Linux, potentially allowing for arbitrary code execution or system crashes.

Executive summary

A high-severity integer underflow vulnerability in the GIMP PSD plugin on Red Hat Enterprise Linux systems may allow attackers to trigger memory corruption or unauthorized system actions.

Vulnerability

The flaw is an integer underflow, categorized as CWE-191, occurring when the software processes malformed PSD files. An authenticated user or local attacker providing a crafted file can trigger this condition, leading to memory corruption.

Business impact

With a CVSS score of 8.4, this vulnerability poses a significant risk to system stability and security. If successfully exploited, it could allow an attacker to gain unauthorized control over the application process, potentially leading to privilege escalation or system-wide compromise depending on the execution context of the GIMP process.

Remediation

Immediate Action: Monitor official Red Hat security advisories for the release of updated packages and apply them to all affected RHEL systems as soon as they become available.

Proactive Monitoring: Scan for anomalous execution patterns in image processing applications and restrict the ability of unauthorized users to execute GIMP with elevated privileges.

Compensating Controls: Implement file integrity monitoring and restrict the processing of untrusted PSD files in high-security environments until patches are applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this issue necessitates a proactive approach to patch management. Security teams should identify all RHEL systems where GIMP is installed and ensure that automated update mechanisms are prepared to deploy the vendor-supplied fix immediately upon release.

More Red Hat CVEs