Impact
A flaw in the GIMP Lighting Effects filter allows an out‑of‑bounds write to occur when processing a specially crafted preset file. The bug arises because the number of light sources in the preset is not properly validated, which can corrupt memory. If an attacker succeeds, a crash is likely and, in some circumstances, arbitrary code execution may be achieved. The exploit requires a user to open the malicious preset file within GIMP.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 6 through 9 where GIMP is installed. No specific GIMP version range is listed, so all current GIMP iterations distributed on these OSes are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is local; an attacker would need to convince a user to open a malicious preset file in GIMP. While the exploit cannot be launched remotely, a compromised or socially engineered user can trigger the memory corruption, leading to program crashes or potential code execution under the user’s privileges.
OpenCVE Enrichment
Debian DSA