Junglewise Threat Intelligence

CVE-2026-0797: GIMP heap-based buffer overflow in ICO file parsing

CVE-2026-0797 · Severity: high · CVSS 8.8 · Published 2026-02-20

Technologies: Red Hat Enterprise Linux AppStream, Gimp. Vendors: Red Hat, Gimp.

Executive brief

GIMP is a popular open-source image editing program used for graphic design and photo manipulation. A security vulnerability in how the software handles ICO (icon) files could allow an attacker to take control of a user's computer if they are tricked into opening a specially crafted malicious image file. This could lead to the theft of sensitive data, installation of malware, or complete system compromise.

Technical details

A heap-based buffer overflow vulnerability exists in GIMP's ICO file parsing component due to insufficient validation of user-supplied data lengths before copying them into a heap buffer. The vulnerability is triggered when the application processes a specially crafted ICO file. While categorized as a local attack vector in some contexts because it requires the user to open a file, it is effectively a remote code execution (RCE) threat if delivered via a malicious website or email attachment. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running GIMP. Patches have been released by the GIMP project and downstream vendors like Red Hat (RHSA-2026:4173, RHSA-2026:5113).

Affected products

  • GIMP GIMP 2.8.22, 3.0.4
  • Red Hat Enterprise Linux AppStream 8, 9

Timeline

  • 2025-12-24: disclosed: Vulnerability reported to vendor
  • 2026-01-30: advisory: Coordinated public release of ZDI advisory
  • 2026-01-30: patched: GIMP project issued a fix via commit 69cc6b1a
  • 2026-02-20: advisory: NVD publication date
  • 2026-03-10: patched: Red Hat released security updates for REL 9

References

Related threats