PT-2026-21332 · Fedora+1 · Fedora+1

Jungwoo Park

·

Published

2026-01-01

·

Updated

2026-03-26

·

CVE-2026-2239

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GIMP versions 3.0.8 through 3.0.8-5 Fedora 43
Description A heap-buffer-overflow exists in the PSD loader component of the software, specifically within the fread pascal string() function due to a missing null terminator. This issue can be exploited by processing crafted PSD files, leading to a denial-of-service (DoS) condition.
Recommendations Update GIMP to a version beyond 3.0.8-5.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2026-2239
OPENSUSE-SU-2026:10195-1
OPENSUSE-SU-2026:20275-1
SUSE-SU-2026:0604-1

Affected Products

Fedora
Gimp