A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
References
Configurations
Configuration 1 (hide)
| AND |
|
History
26 May 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 May 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
14 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 May 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 Apr 2026, 13:11
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:gimp:gimp:3.2.0:rc3:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:gimp:gimp:3.2.0:rc2:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* cpe:2.3:a:gimp:gimp:3.2.0:rc1:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:* |
|
| Summary |
|
|
| First Time |
Redhat
Redhat enterprise Linux Gimp gimp Gimp |
|
| References | () https://access.redhat.com/security/cve/CVE-2026-4887 - Mitigation, Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2451669 - Issue Tracking, Vendor Advisory | |
| References | () https://gitlab.gnome.org/GNOME/gimp/-/issues/15960 - Exploit, Issue Tracking |
26 Mar 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-26 13:16
Updated : 2026-05-26 10:16
NVD link : CVE-2026-4887
Mitre link : CVE-2026-4887
CVE.ORG link : CVE-2026-4887
JSON object : View
Products Affected
gimp
- gimp
redhat
- enterprise_linux
CWE
CWE-193
Off-by-one Error
