Junglewise Threat Intelligence

CVE-2026-18301: GIMP integer overflow in PSD file parsing

CVE-2026-18301 · Severity: high · CVSS 7.8 · Published 2026-08-20

Technologies: Gimp. Vendors: Gimp.

Executive brief

GIMP is a widely-used open-source image editor. This vulnerability in its PSD file parser allows attackers to execute arbitrary code when a user opens a specially-crafted PSD file, potentially compromising the user's system and any sensitive data accessible through GIMP.

Technical details

An integer overflow vulnerability exists in GIMP's PSD file parsing, specifically in the `read_channel_data` function. The flaw stems from insufficient validation of user-supplied data when allocating buffers for channel data, allowing an attacker to trigger an integer overflow before buffer allocation. The attack requires user interaction—the victim must open a malicious PSD file. An attacker can leverage this to execute arbitrary code in the context of the GIMP process. GIMP has released a patch that increases vulnerable variables from guint32 to gsize and adds graceful failure handling for memory allocation errors.

Affected products

  • GIMP GIMP

Timeline

  • 2026-04-17: disclosed: Vulnerability reported to vendor
  • 2026-07-29: patched: Patch released via merge request
  • 2026-07-29: advisory: Coordinated public release of advisory

References

Related threats