CVE-2026-58380

Name
CVE-2026-58380
Description
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://access.redhat.com/security/cve/CVE-2026-58380
secalert@redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2496135
secalert@redhat.com https://gitlab.gnome.org/GNOME/gimp/-/commit/83699817
secalert@redhat.com https://gitlab.gnome.org/GNOME/gimp/-/issues/16206
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:40751

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gimp:gimp:3.2.4:*:*:*:*:*:*:* gimp == None == 3.2.4
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* enterprise_linux == None == 7.0
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* enterprise_linux == None == 8.0
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* enterprise_linux == None == 9.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gimp edge-community 3.2.4-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gimp edge-community 3.2.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gimp 3.24-community 3.2.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable