Project Subscriptions
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4483-1 | gimp security update |
Debian DSA |
DSA-6139-1 | gimp security update |
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Mon, 30 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 26 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an out-of-bounds read when strlen() is subsequently called. Successfully exploiting this vulnerability can cause the application to crash, resulting in an application level Denial of Service. |
| Title | gimp: GIMP: Application crash (DoS) via crafted PSD file due to heap-buffer-overflow | Gimp: gimp: application crash (dos) via crafted psd file due to heap-buffer-overflow |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
Tue, 10 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gimp
Gimp gimp |
|
| Vendors & Products |
Gimp
Gimp gimp |
Mon, 09 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | gimp: GIMP: Application crash (DoS) via crafted PSD file due to heap-buffer-overflow | |
| Weaknesses | CWE-170 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-03-30T11:29:20.235Z
Reserved: 2026-02-09T09:07:05.426Z
Link: CVE-2026-2239
Updated: 2026-03-30T11:29:16.114Z
Status : Awaiting Analysis
Published: 2026-03-26T21:17:04.483
Modified: 2026-03-30T13:26:50.827
Link: CVE-2026-2239
OpenCVE Enrichment
Updated: 2026-02-10T21:45:59Z
Debian DLA
Debian DSA