CVE-2026-59091

7.3

Red Hat · Red Hat Enterprise Linux (GIMP plugins)

A flaw in GIMP file format plugins, specifically for PSD and PAA files, allows for out-of-bounds writes that can be triggered by processing malicious files.

Executive summary

Memory corruption vulnerabilities in GIMP file format plugins across multiple versions of Red Hat Enterprise Linux pose a risk of arbitrary code execution through malicious image files.

Vulnerability

The vulnerability is an out-of-bounds write (CWE-787) occurring within GIMP's file format plugins, specifically when handling PSD or PAA files. This requires a local user to open a specially crafted image file, which then triggers the memory corruption.

Business impact

The CVSS score of 7.3 reflects the high impact of memory corruption, which can lead to system crashes or arbitrary code execution. If an attacker successfully tricks a user into opening a malicious image file, they could gain the same privileges as the user, leading to potential data compromise or further system-level exploitation.

Remediation

Immediate Action: Apply the relevant security updates provided by Red Hat for the GIMP package across all affected RHEL versions.

Proactive Monitoring: Review system logs for application crashes related to GIMP or image processing tasks.

Compensating Controls: Restrict users from opening image files from untrusted sources and ensure that anti-virus or endpoint detection solutions are configured to scan image files for known malicious patterns.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should ensure that the GIMP software is updated across their RHEL fleet to address the out-of-bounds write vulnerability. Users should be cautioned against opening image files from unverified or suspicious sources until the software has been patched.

More Red Hat CVEs