CVE-2026-2271

A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write. Successful exploitation could result in an application level denial of service.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:gimp:gimp:3.2.0:rc2:*:*:*:*:*:*

History

21 Apr 2026, 15:24

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2026-2271 - () https://access.redhat.com/security/cve/CVE-2026-2271 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2438429 - () https://bugzilla.redhat.com/show_bug.cgi?id=2438429 - Exploit, Issue Tracking, Vendor Advisory
References () https://gitlab.gnome.org/GNOME/gimp/-/issues/15732 - () https://gitlab.gnome.org/GNOME/gimp/-/issues/15732 - Exploit, Issue Tracking
First Time Gimp gimp
Gimp
CPE cpe:2.3:a:gimp:gimp:3.2.0:rc2:*:*:*:*:*:*

30 Mar 2026, 13:26

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en el analizador de archivos PSP (Paint Shop Pro) de GIMP. Un atacante remoto podría explotar una vulnerabilidad de desbordamiento de entero en la función read_creator_block() al proporcionar un archivo de imagen PSP especialmente diseñado. Esta vulnerabilidad ocurre cuando un valor de longitud de 32 bits del archivo se utiliza para la asignación de memoria sin una validación adecuada, lo que lleva a un desbordamiento de montículo y una escritura fuera de límites. La explotación exitosa podría resultar en una denegación de servicio a nivel de aplicación.

26 Mar 2026, 22:16

Type Values Removed Values Added
References
  • () https://gitlab.gnome.org/GNOME/gimp/-/issues/15732 -

26 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 21:17

Updated : 2026-06-17 10:30


NVD link : CVE-2026-2271

Mitre link : CVE-2026-2271

CVE.ORG link : CVE-2026-2271


JSON object : View

Products Affected

gimp

  • gimp
CWE
CWE-190

Integer Overflow or Wraparound