Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this vulnerability, do not navigate to directories containing PSD files from untrusted sources using the GIMP file chooser. Additionally, users can disable thumbnail generation in the preferences to prevent the vulnerable code path from being reached.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 15 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution. | |
| Title | Gimp: integer overflow when generating a thumbnail preview for a psd file | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-15T22:10:07.541Z
Reserved: 2026-09-15T20:33:46.946Z
Link: CVE-2026-92248
No data.
Status : Received
Published: 2026-09-15T22:17:04.190
Modified: 2026-09-15T22:17:04.190
Link: CVE-2026-92248
OpenCVE Enrichment
No data.
-
CWE-190
Integer Overflow or Wraparound