CVE-2026-90949
Received Received - Intake

Heap-based Buffer Overflow in GIMP PSP File Loader

Vulnerability report for CVE-2026-90949, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: redhat-SADP

Description

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. A remote attacker could exploit this vulnerability by crafting a malicious PSP file. Opening this file in GIMP could lead to a crash or arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnome gimp *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap-based buffer overflow in GIMP's PSP file loader. When processing a compressed selection channel, the allocated buffer size doesn't match the decompressed data size. A crafted PSP file can exploit this to cause a crash or run arbitrary code.

Detection Guidance

Detecting this vulnerability requires monitoring for unusual activity when processing PSP files in GIMP. Check for crashes or errors when opening PSP files. Use system logs to identify heap-based buffer overflow events. No specific commands are provided in the resources, but monitoring GIMP's behavior with PSP files may help.

Impact Analysis

Opening a malicious PSP file in GIMP could crash the application or allow an attacker to execute arbitrary code on your system. This could lead to data theft, system compromise, or denial of service.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Compliance may be compromised if systems are exploited.

Mitigation Strategies

Immediate mitigation steps include avoiding opening untrusted PSP files in GIMP. Since no official fixes are available, consider upgrading to supported versions if possible. Monitor Red Hat's advisories for updates. Disable PSP file handling in GIMP if feasible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90949. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart