Junglewise Threat Intelligence

CVE-2026-6384: GIMP buffer overflow in GIF ReadJeffsImage function

CVE-2026-6384 · Severity: high · CVSS 7.3 · Published 2026-04-15

Technologies: Gimp, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8. Vendors: Gimp, Red Hat.

Executive brief

GIMP, a popular open-source image editor, is vulnerable to a security flaw when processing GIF images. An attacker can create a malicious GIF file that, when opened by a user, could crash the application or allow the attacker to take control of the computer. This poses a risk to data confidentiality and system stability for users who open untrusted image files.

Technical details

A classic buffer overflow (CWE-120) exists in GIMP's GIF image loading component within the ReadJeffsImage function. The vulnerability is triggered when the application processes a specially crafted GIF file, allowing an attacker to write data beyond the boundaries of an allocated buffer. This is a local attack vector that requires user interaction (opening a malicious file). Successful exploitation can lead to arbitrary code execution or a denial of service (application crash). Red Hat has identified Red Hat Enterprise Linux 6 and 8 as affected, while versions 7 and 9 are unaffected.

Affected products

  • GIMP GIMP -
  • Red Hat Red Hat Enterprise Linux 6 affected
  • Red Hat Red Hat Enterprise Linux 8 affected

Timeline

  • 2026-04-15: disclosed: Initial disclosure date
  • 2026-04-15: advisory: NVD and Red Hat published advisories

References

Related threats