Executive brief
GIMP is a popular open-source image editing application. A vulnerability in how it processes animated cursor (ANI) files could allow an attacker to take control of a user's computer if the user is tricked into opening a malicious file or visiting a compromised website. This could lead to the theft of sensitive data or the installation of malware.
Technical details
An integer overflow vulnerability exists in GIMP's ANI file parsing component due to insufficient validation of user-supplied data. The flaw occurs when the application calculates the size for a buffer allocation, leading to a heap-based buffer overflow. An attacker can exploit this by providing a specially crafted ANI file, which requires the victim to manually open the file or interact with a malicious webpage. Successful exploitation allows for arbitrary code execution within the context of the current process. Patches have been released by GIMP and Red Hat (RHSA-2026:16484, RHSA-2026:19362).
Affected products
- GIMP GIMP 3.0.8
- Red Hat Red Hat Enterprise Linux AppStream (v. 9) gimp-3.0.4-1.el9_7.5
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 8
Timeline
- 2026-03-05: disclosed: Vulnerability reported to vendor
- 2026-03-19: advisory: Coordinated public release of ZDI advisory
- 2026-04-11: advisory: NVD publication date
- 2026-05-12: patched: Red Hat release of RHSA-2026:16484
References
- https://gitlab.gnome.org/GNOME/gimp/-/commit/09e5459de913172fc51da3bd6b6adc533acd368e
- https://www.zerodayinitiative.com/advisories/ZDI-26-218/
- https://access.redhat.com/errata/RHSA-2026:16484
- https://access.redhat.com/errata/RHSA-2026:19362
- https://access.redhat.com/security/cve/CVE-2026-4151
- https://bugzilla.redhat.com/show_bug.cgi?id=2457532
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4151.json