Low severity3.3NVD Advisory· Published Mar 26, 2026· Updated Apr 21, 2026
CVE-2026-2271
CVE-2026-2271
Description
A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write. Successful exploitation could result in an application level denial of service.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingVendor Advisory
- gitlab.gnome.org/GNOME/gimp/-/issues/15732nvdExploitIssue Tracking
- access.redhat.com/security/cve/CVE-2026-2271nvdVendor Advisory
News mentions
0No linked articles in our index yet.