Description
A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Do not load GIMPressionist preset files from untrusted sources.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 24 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution. | |
| Title | Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-24T08:30:29.489Z
Reserved: 2026-09-24T08:09:01.599Z
Link: CVE-2026-97185
No data.
Status : Received
Published: 2026-09-24T09:17:08.937
Modified: 2026-09-24T09:17:08.937
Link: CVE-2026-97185
No data.
OpenCVE Enrichment
Updated: 2026-09-24T09:30:20Z
Weaknesses
-
CWE-787
Out-of-bounds Write