Junglewise Threat Intelligence

CVE-2026-2047: GIMP heap buffer overflow in ICNS file parsing

CVE-2026-2047 · Severity: high · CVSS 7.8 · Published 2026-02-20

Technologies: Red Hat Enterprise Linux 6, Gimp, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9. Vendors: Red Hat, Gimp.

Executive brief

GIMP, a popular open-source image editor, is vulnerable to a security flaw when processing Apple Icon Image (ICNS) files. If a user opens a specially crafted malicious image file, an attacker could take control of the computer or execute unauthorized commands. This could lead to the theft of personal data or a complete system compromise depending on the user's permissions.

Technical details

A heap-based buffer overflow exists in GIMP's ICNS file format parser due to insufficient validation of user-supplied data lengths before copying them into a heap buffer. Specifically, the importer failed to verify that ICNS resource data sizes were greater than zero, potentially leading to infinite loops or memory corruption. An attacker can exploit this by tricking a user into opening a malformed ICNS file, leading to arbitrary code execution within the context of the GIMP process. Patches have been released by GIMP (via merge request 2600) and Red Hat (RHSA-2026:4173).

Affected products

  • GIMP GIMP 3.0.6
  • Red Hat Red Hat Enterprise Linux 9 AppStream
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7

Timeline

  • 2025-12-04: disclosed: Vulnerability reported to vendor
  • 2026-01-17: patched: GIMP merge request submitted to resolve the issue
  • 2026-02-19: advisory: ZDI advisory published
  • 2026-02-20: disclosed: NVD publication date
  • 2026-03-10: patched: Red Hat released security updates (RHSA-2026:4173)

References

Related threats