Executive brief
GIMP is a widely-used image editing tool. A flaw in how GIMP processes TIF (Tagged Image File Format) image files allows attackers to craft malicious image files that trigger an integer overflow, enabling arbitrary code execution. An attacker would trick users into opening a malicious image file, potentially compromising the user's system and granting full access to their data and applications.
Technical details
A integer overflow vulnerability exists in GIMP's TIF file parser due to insufficient validation of user-supplied data before buffer allocation. When parsing specially crafted TIF files, an integer overflow can occur during size calculations, leading to undersized buffer allocation. This allows an attacker to write beyond the allocated buffer, achieving arbitrary code execution in the context of the GIMP process. The attack requires user interaction (opening a malicious TIF file) but does not require elevated privileges. A patch is available from the GIMP project repository.
Affected products
- GIMP GIMP
Timeline
- 2026-04-17: disclosed: Vulnerability reported to vendor
- 2026-07-29: patched: Patch made available; coordinated public disclosure
- 2026-07-29: advisory: ZDI-26-461 advisory published