High severity7.3NVD Advisory· Published Jul 3, 2026· Updated Jul 13, 2026
CVE-2026-58379
CVE-2026-58379
Description
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.
Affected products
5- osv-coords4 versionspkg:rpm/almalinux/gimppkg:rpm/almalinux/gimp-libspkg:rpm/opensuse/gimp&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/gimp&distro=openSUSE%20Tumbleweed
< 2:3.0.4-4.el9_8.5+ 3 more
- (no CPE)range: < 2:3.0.4-4.el9_8.5
- (no CPE)range: < 2:3.0.4-4.el9_8.5
- (no CPE)range: < 3.0.8-bp160.5.1
- (no CPE)range: < 3.2.4-2.1
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.