Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this vulnerability, users should avoid opening untrusted or suspicious PSD image files with GIMP. As a general security practice, it is recommended to only process image files from trusted sources.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system. | |
| Title | Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-191 | |
| CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-10T12:59:43.222Z
Reserved: 2026-07-02T15:11:12.821Z
Link: CVE-2026-59090
Updated: 2026-08-10T12:59:39.189Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T13:30:05Z
-
CWE-191
Integer Underflow (Wrap or Wraparound)