CVE-2026-58384

Name
CVE-2026-58384
Description
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://access.redhat.com/security/cve/CVE-2026-58384
secalert@redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2497431
secalert@redhat.com https://gitlab.gnome.org/GNOME/gimp/-/commit/da29e217
secalert@redhat.com https://gitlab.gnome.org/GNOME/gimp/-/issues/16216
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:40751

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gimp:gimp:3.2.4:*:*:*:*:*:*:* gimp == None == 3.2.4
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* enterprise_linux == None == 9.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gimp edge-community 3.2.4-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gimp edge-community 3.2.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gimp 3.24-community 3.2.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable