Executive brief
A security vulnerability exists in GIMP, a popular open-source image editor, specifically within its tool for opening Paint Shop Pro (PSP) files. By tricking a user into opening a specially crafted image file, an attacker could crash the application or potentially run unauthorized code on the user's computer. This flaw could lead to a loss of data, system instability, or a full compromise of the user's workstation.
Technical details
A heap-based buffer overflow exists in the 'read_channel_data()' function within 'plug-ins/common/file-psp.c' of GIMP. The vulnerability is caused by an incorrect buffer size calculation for low bit-depth images (1-bit or 4-bit); while the allocation ('line_width') uses a packed bit-depth formula, the subsequent 'fread()' call attempts to read 'width' bytes (one byte per pixel). This results in a heap overwrite when the image width exceeds the packed byte count. This flaw is a variant/bypass of CVE-2026-4153, as the previous fix addressed 'read_layer_block()' but left the intermediate buffer in 'read_channel_data()' vulnerable. A patch has been developed to ensure the buffer allocation accounts for the full pixel width.
Affected products
- GNOME GIMP 3.2.1
- Red Hat Red Hat Enterprise Linux 9 affected
Timeline
- 2026-07-01: disclosed: Reported via Red Hat Bugzilla
- 2026-07-03: advisory: NVD and Red Hat published advisory details
- 2026-07-03: patched: Upstream fix committed to GNOME GIMP repository