Executive brief
GIMP is a popular image editing application used by designers and content creators. A vulnerability in SGI image file parsing allows attackers to execute arbitrary code when a user opens a malicious image file, potentially compromising the user's system and any sensitive image data being edited.
Technical details
An integer overflow vulnerability exists in GIMP's SGI file parser due to insufficient validation of user-supplied data before memory operations. The vulnerability is triggered when parsing a malicious SGI file, allowing an integer overflow to occur prior to a write operation. Exploitation requires user interaction—the target must open a crafted SGI image file or visit a malicious page hosting the file. A successful exploit executes arbitrary code within the context of the GIMP process with the privileges of the running user. GIMP has released a patch available on their GitLab repository.
Affected products
- GIMP GIMP
Timeline
- 2026-04-17: disclosed: Vulnerability reported to vendor
- 2026-07-29: advisory: Coordinated public release of advisory
- 2026-07-29: patched: GIMP issued update; fix available at gitlab.gnome.org/GNOME/gimp/-/commit/76531da9732f38566e5fd8f8f80c837158511ae5