A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Do not load GIMPressionist preset files from untrusted sources.
References
History
Thu, 24 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution. | |
| Title | Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-24T08:30:29.489Z
Reserved: 2026-09-24T08:09:01.599Z
Link: CVE-2026-97185
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses