7.3highHigh

CVE-2026-58380

Gimp Gimp

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

Exploitation status

  • Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, someone has to be persuaded to take an action first.

Scoring

CVSS
7.3 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness
CWE-193
Assigned by
secalert@redhat.com

Dates

Published
2026-07-06
Last modified
2026-09-02
Sources
NVD

Affected products

  • Gimp Gimp3.2.4
  • Redhat Enterprise Linux7.0, 8.0, 9.0

As listed in the NVD configuration data. Not a statement about your estate.

References