Junglewise Threat Intelligence

CVE-2026-58381: GNOME GIMP double-free in PSP file format parser

CVE-2026-58381 · Severity: medium · CVSS 6.1 · Published 2026-07-02

Technologies: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9. Vendors: Red Hat, Gnome.

Executive brief

GIMP, a popular open-source image editor, contains a security flaw in how it handles Paint Shop Pro (PSP) files. If a user is tricked into opening a specially crafted, malicious PSP file, the application could crash or potentially allow an attacker to take control of the system. This vulnerability impacts the reliability of the software and could be used as a starting point for further attacks on a user's computer.

Technical details

A double-free vulnerability exists in GIMP's PSP file format parser within the 'read_layer_block()' function in 'plug-ins/common/file-psp.c'. The flaw is caused by a failure to reset a pointer ('name') to NULL at the start of a processing loop. When a specially crafted PSP file triggers an error (such as a truncated file) during the second iteration of the loop, the 'fread' operation fails before a new memory allocation occurs. This causes the error-handling path to call 'g_free()' on a pointer that was already freed at the end of the previous iteration. An attacker can exploit this via a local attack vector requiring user interaction (opening a file) to cause a denial of service or achieve arbitrary code execution through heap corruption. A fix has been committed to the upstream GNOME GIMP repository.

Affected products

  • GNOME GIMP 3.2.1
  • Red Hat Red Hat Enterprise Linux 7 affected
  • Red Hat Red Hat Enterprise Linux 8 affected
  • Red Hat Red Hat Enterprise Linux 9 affected

Timeline

  • 2026-07-01: disclosed: Reported to Red Hat Bugzilla
  • 2026-07-02: advisory: NVD and Red Hat published advisory details
  • 2026-07-02: patched: Upstream fix committed to GNOME GitLab repository

References