PT-2026-33128 · Red Hat · Red Hat Enterprise Linux 6+3

Published

2026-04-15

·

Updated

2026-04-15

·

CVE-2026-40917

CVSS v3.1

5.0

Medium

AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the icns slurp() function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-40917

Affected Products

Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9