CVE-2026-59087

Name
CVE-2026-59087
Description
A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://access.redhat.com/security/cve/CVE-2026-59087
secalert@redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2496576
secalert@redhat.com https://gitlab.gnome.org/GNOME/gimp/-/work_items/16491

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gimp:gimp:3.2.4:*:*:*:*:*:*:* gimp == None == 3.2.4
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* enterprise_linux == None == 7.0
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* enterprise_linux == None == 8.0
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* enterprise_linux == None == 9.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gimp edge-community 3.2.4-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gimp edge-community 3.2.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gimp 3.24-community 3.2.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable