Impact
This vulnerability occurs in GIMP’s file‑psd plugin when an attacker supplies a specially crafted PSD file that contains an incorrect channel‑count value. The plugin fails to validate this parameter, leading to improper memory bounds checking and a heap out‑of‑bounds read and a stack out‑of‑bounds access. The resulting behavior can crash the application and, depending on memory contents, may expose limited information. The weakness is a classic input validation flaw (CWE‑120).
Affected Systems
Systems that run Red Hat Enterprise Linux 6, 7, 8, or 9 and have GIMP installed are potentially affected. The vulnerability resides in the GIMP package included in these RHEL distributions; specific GIMP version numbers were not disclosed, so all currently shipped releases should be reviewed.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate impact. Exploitation requires an attacker to provide a crafted PSD file, which an attacker can do locally or send over a network if the victim chooses to open the file. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalogue, suggesting no known widespread exploitation yet. Nevertheless, the local nature of the attack, coupled with the crash or limited disclosure, could allow a malicious user or automated tool to cause denial‑of‑service on the victim system.
OpenCVE Enrichment