Executive brief
GIMP, a popular open-source image editor, is vulnerable to a security flaw when processing PaintShop Pro (PSP) files. An attacker can create a malicious image file that, when opened by a user, allows the attacker to take control of the computer or run unauthorized software. This could lead to the theft of personal data or a complete system compromise if a user is tricked into opening a specially crafted file.
Technical details
A heap-based buffer overflow vulnerability exists in GIMP's handling of PaintShop Pro (PSP) files. The flaw is caused by insufficient validation of user-supplied data lengths before copying them into a heap-based buffer during file parsing. An attacker can exploit this by inducing a user to open a specially crafted PSP file, leading to out-of-bounds memory writes. Successful exploitation allows for arbitrary code execution within the context of the GIMP process. Patches have been released by the GIMP project and downstream maintainers like Red Hat to address the issue by improving input validation.
Affected products
- GIMP GIMP 3.0.6, 3.0.4, 2.99.8
- Red Hat Enterprise Linux 6, 9, 9.0, 9.2, 9.4, 9.6, 9.8
Timeline
- 2025-11-11: disclosed: Vulnerability reported to vendor
- 2025-12-29: advisory: Coordinated public release by ZDI
- 2025-12-29: patched: GIMP project commit released
- 2026-01-23: advisory: NVD publication
- 2026-02-16: patched: Red Hat released security updates (RHSA-2026:2707)
References
- https://gitlab.gnome.org/GNOME/gimp/-/commit/03575ac8cbb0ef3103b0a15d6598475088dcc15e
- https://www.zerodayinitiative.com/advisories/ZDI-25-1196/
- https://access.redhat.com/errata/RHSA-2026:2707
- https://access.redhat.com/errata/RHSA-2026:2930
- https://access.redhat.com/errata/RHSA-2026:2950
- https://access.redhat.com/errata/RHSA-2026:2953
- https://access.redhat.com/errata/RHSA-2026:2969