PT-2025-44348 · Gimp+7 · Gimp+7

Published

2025-09-02

·

Updated

2026-03-04

·

CVE-2025-10934

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description This issue allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this, as the target must visit a malicious page or open a malicious file. The flaw exists within the parsing of XWD files, resulting from insufficient validation of user-supplied data length before copying it to a heap-based buffer. An attacker can leverage this to execute code in the context of the current process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:21968
ALSA-2025:22417
BDU:2025-13877
CESA-2025_22417
CVE-2025-10934
DLA-4362-1
DSA-6049-1
INFSA-2025_21968
INFSA-2025_22417
MGASA-2026-0012
OESA-2025-2639
OESA-2025-2640
OESA-2025-2641
OESA-2025-2642
RHSA-2025_21968
RHSA-2026:0027
RHSA-2026:0250
RHSA-2026:0356
SUSE-SU-2025:4137-1
SUSE-SU-2026:0684-1
USN-8075-1
ZDI-25-978

Affected Products

Almalinux
Centos
Gimp
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu