Junglewise Threat Intelligence

CVE-2026-2045: GIMP out-of-bounds write in XWD file parsing

CVE-2026-2045 · Severity: high · CVSS 7.3 · Published 2026-02-20

Technologies: Red Hat Enterprise Linux, Gimp. Vendors: Red Hat, Gimp.

Executive brief

GIMP, a popular open-source image editor, is vulnerable to a security flaw when processing certain image files. An attacker could create a specially crafted XWD image file that, when opened by a user, allows the attacker to take control of the computer. This could lead to the theft of sensitive data or the installation of malicious software.

Technical details

An out-of-bounds write vulnerability exists in GIMP's XWD (X Window Dump) file parsing component. The flaw is caused by insufficient validation of user-supplied data within the XWD parser, leading to a write operation past the end of an allocated buffer. To exploit this, an attacker must convince a user to open a malicious XWD file or visit a page that triggers the file's processing. Successful exploitation allows for arbitrary code execution in the context of the current process. Patches have been released by GIMP and downstream distributors like Red Hat.

Affected products

  • GIMP GIMP 2.8, 3.0.4
  • Red Hat Enterprise Linux 8, 9

Timeline

  • 2025-11-11: disclosed: Vulnerability reported to vendor
  • 2026-02-19: advisory: Coordinated public release by Zero Day Initiative
  • 2026-02-19: patched: GIMP commit 68b27dfb released to address the issue
  • 2026-03-10: patched: Red Hat released security updates for RHEL 9 (RHSA-2026:4173)

References

Related threats