Description
A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. A remote attacker could exploit this vulnerability by crafting a malicious PSP file. Opening this file in GIMP could lead to a crash or arbitrary code execution.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A heap-based buffer overflow is present in GIMP’s Paint Shop Pro file loader. When a compressed selection channel is processed, the allocated buffer is smaller than the decompressed data, allowing a remote attacker to craft a malicious PSP file that can trigger the overflow. If the file is opened, the overflow can lead to a program crash or arbitrary code execution on the host system. The vulnerability is a classic example of CWE-787, where insufficient bounds checking on reference allocations occurs.

Affected Systems

The flaw affects GIMP running on Red Hat Enterprise Linux releases 6 through 9, as disclosed by Red Hat. The impact is limited to installations of GIMP on these platforms; users of other operating systems are not directly affected.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity infection vector. The EPSS score is < 1%, indicating a very low, yet nonzero, exploitation probability, and the issue is not listed in CISA’s KEV catalogue, but the vulnerability can be triggered by a malicious PSP file delivered to a user. A remote attacker need only entice a victim to open the file, making the risk significant for environments where GIMP is used to process external artwork. Without a patch, exploitation remains feasible.

Generated by OpenCVE AI on September 15, 2026 at 14:56 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Upgrade GIMP to the latest available release that contains the PSP loader fix for the affected RHEL versions.
  • No official workaround is available from Red Hat; the available options do not meet security criteria for ease of use, deployment, or stability.
  • Avoid opening PSP files from untrusted sources and disable PSP support in GIMP, or run GIMP within a container or sandbox (e.g., Firejail) when processing files of unknown origin to contain any potentially malicious code.

Generated by OpenCVE AI on September 15, 2026 at 14:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. A remote attacker could exploit this vulnerability by crafting a malicious PSP file. Opening this file in GIMP could lead to a crash or arbitrary code execution.
Title Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mismatch
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-787
CPEs cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-01T09:59:37.507Z

Reserved: 2026-09-14T11:41:23.277Z

Link: CVE-2026-90949

cve-icon Vulnrichment

Updated: 2026-09-16T15:01:51.259Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T14:17:20.840

Modified: 2026-10-01T11:17:29.397

Link: CVE-2026-90949

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-14T12:34:00Z

Links: CVE-2026-90949 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:00:17Z

Weaknesses