CVE-2026-58384 Details
Description
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
A heap buffer overflow vulnerability has been identified in GIMP's PSD file parser, specifically within the 'read_RLE_channel()' function of 'psd-load.c'. This vulnerability arises from an integer overflow in the calculation of row lengths for RLE channels, which can lead to an undersized memory allocation. When a crafted PSD file is opened, this flaw allows for heap memory corruption, potentially enabling denial-of-service conditions or arbitrary code execution.
Users can update to GIMP versions 3.2.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:40751 | [email protected] | |
| https://access.redhat.com/security/cve/CVE-2026-58384 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2497431 | [email protected] | Issue TrackingThird Party Advisory |
| https://gitlab.gnome.org/GNOME/gimp/-/commit/da29e217 | [email protected] | Broken Link |
| https://gitlab.gnome.org/GNOME/gimp/-/issues/16216 | [email protected] | ExploitIssue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gimp gimp | 3.2.4 |
CPE
Remediation
| |
| redhat enterprise linux | 9.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | CVE Modified | [email protected] |
| Jul 10, 2026 | Initial Analysis | [email protected] |
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2026 | New CVE Received | [email protected] |