CVE-2026-40915
Description
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data. Successful exploitation could result in a denial of service (DoS) or potentially arbitrary code execution.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description gimp: GIMP: Heap buffer overflow due to integer overflow in FITS image loader Red Hat statement Moderate. This flaw in GIMP's FITS image loader could lead to a denial of service or arbitrary code execution when processing a specially crafted FITS file. Exploitation requires user interaction, as a malicious file must be opened by the application. Red Hat Enterprise Linux systems areβ¦
Description
gimp: GIMP: Heap buffer overflow due to integer overflow in FITS image loader
Red Hat statement
Moderate. This flaw in GIMP's FITS image loader could lead to a denial of service or arbitrary code execution when processing a specially crafted FITS file. Exploitation requires user interaction, as a malicious file must be opened by the application. Red Hat Enterprise Linux systems are affected if GIMP is installed and used to open untrusted FITS image files.
CVSS v3: 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | gimp | Fix deferred |
| Red Hat Enterprise Linux 7 | gimp | Fix deferred |
| Red Hat Enterprise Linux 8 | gimp:2.8/gimp | Fix deferred |
| Red Hat Enterprise Linux 9 | gimp | Fix deferred |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | affected | |
| debian | bullseye | affected | |
| debian | forky | fixed | 3.2.2-1 |
| debian | sid | fixed | 3.2.2-1 |
| debian | trixie | affected | |
| rhel | 6.0 | affected | |
| rhel | 7.0 | affected | |
| rhel | 8.0 | affected | |
| rhel | 9.0 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| gimp | gimp | - | |
References
CWEs
CWE-190
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.