PT-2026-21475 · Gimp · Gimp

Published

2026-01-01

·

Updated

2026-03-26

·

CVE-2026-2271

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GIMP (affected versions not specified)
Description A flaw exists in GIMP's PSP (Paint Shop Pro) file parser. An attacker can trigger an integer overflow in the read creator block() function by supplying a crafted PSP image file. This occurs because a 32-bit length value from the file is used for memory allocation without sufficient validation, resulting in a heap overflow and an out-of-bounds write. Successful exploitation may lead to a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-2271
SUSE-SU-2026:0604-1

Affected Products

Gimp