CVE-2026-2239 Details
Description
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an out-of-bounds read when strlen() is subsequently called. Successfully exploiting this vulnerability can cause the application to crash, resulting in an application level Denial of Service.
A heap-buffer-overflow vulnerability has been identified in GIMP, specifically within the fread_pascal_string function of the PSD file handling plugin. This vulnerability arises when the function processes a specially crafted Photoshop Document (PSD) file. The issue occurs because the buffer allocated for Pascal strings is not properly null-terminated, which leads to an out-of-bounds read when the strlen() function is called. Exploiting this vulnerability causes the application to crash, creating a denial-of-service condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-2239 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2437675 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://gitlab.gnome.org/GNOME/gimp/-/issues/15812 | [email protected] | ExploitIssue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-170 | Improper Null Termination | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gimp gimp | 3.2.0 rc3 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 9.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | CVE Modified | [email protected] |
| Mar 26, 2026 | New CVE Received | [email protected] |