Sceawere

Vulnerability Detail

CVE-2026-59091UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GIMP File Format Plugin Vulnerabilities

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
4h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 6
Attack Type
Out-of-bounds Write
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-08-10T19:17:30.090Z",
  "pubdate": "2026-08-10T19:17:30.090Z",
  "executiveSummary": "A vulnerability has been identified within multiple file format plugins of GIMP, specifically impacting parsers designed for PSD and PAA files. This security flaw manifests as a lack of proper input validation and bounds checking during the parsing of malformed image structures within these proprietary and specialized formats.\nThe primary impact of this vulnerability is the potential for unexpected application behavior, which under specific exploitation conditions can extend to memory corruption or arbitrary code execution within the context of the user running the application. The affected systems include any deployment of GIMP utilizing vulnerable file format plugins for image processing.\nThe risk implications are moderate to high depending on the privileges of the victim and the exact nature of the memory corruption achieved, potentially leading to a compromise of user-level confidentiality, integrity, and availability.\nThe attacker capabilities required to exploit this vulnerability involve the creation of a specially crafted image file structured to trigger the parsing flaw. Exploitation requirements mandate user interaction, specifically tricking a victim into opening the malicious image file using GIMP, without requiring prior authentication, specialized network exposure, or elevated privileges beyond standard user execution.",
  "technicalDetails": "The root cause of the vulnerability resides in the internal file format plugins of GIMP responsible for handling PSD (Photoshop Document) and PAA (Real Virtuality engine texture) files. These components fail to adequately validate metadata, header lengths, or chunk sizes supplied within the malicious image structure before allocating memory or copying data into internal buffers.\nThe vulnerable component comprises the specific parsing logic within the GIMP file format plugins designed to decode complex image layers, compression schemes, or color palettes specific to PSD and PAA formats. Because these parsers process untrusted input directly from disk or via automated file loading routines, malformed inputs can easily trigger buffer overflows, out-of-bounds reads, or integer overflows.\nThe attack flow proceeds as follows: First, an attacker generates a specially crafted image file (either PSD or PAA) containing anomalous header values, oversized chunk descriptors, or corrupted structural offsets. Second, the attacker delivers this file to the victim via social engineering, spear-phishing, or malicious web downloads. Third, the victim opens the crafted image file using GIMP. Fourth, upon attempting to parse the file, GIMP invokes the vulnerable file format plugin. Fifth, the plugin processes the malformed structures without sufficient bounds checking, resulting in memory corruption or abnormal application termination. If weaponized effectively, the memory corruption can be leveraged to alter control flow and execute arbitrary shellcode or payloads.\nRegarding environmental and access constraints, the vulnerability requires no authentication or special privileges. The attack vector is localized to the client machine and relies on local file processing, though it can be triggered automatically if GIMP or a dependent library is invoked via web browsers or file managers configured to preview or open PSD and PAA files. No network exposure is inherently required for the exploitation vector unless combined with secondary remote file inclusion or browser helper integration."
}
CVE-2026-59091: GIMP File Format Plugin Vulnerabilities (HIGH Severity, CVSS: 7.3) - Sceawere