CVE-2025-48798
published 2025-05-27CVE-2025-48798: A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be…
PriorityP337high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.18%
7.3th percentile
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.10.34-1+deb12u3 (bookworm) | gimp 2.10.34-1+deb12u3 (bookworm) |
| gimp | gimp | >= 0 < 2.10.22-4+deb11u3 | 2.10.22-4+deb11u3 |
| gimp | gimp | >= 0 < 2.10.34-1+deb12u3 | 2.10.34-1+deb12u3 |
| gimp | gimp | >= 0 < 3.0.0~RC1-4 | 3.0.0~RC1-4 |
| gimp | gimp | >= 0 < 3.0.0~RC1-4 | 3.0.0~RC1-4 |
| gimp | gimp | >= 0 < 2.8.16-1ubuntu1.1+esm2 | 2.8.16-1ubuntu1.1+esm2 |
| gimp | gimp | >= 0 < 2.8.22-1ubuntu0.1~esm2 | 2.8.22-1ubuntu0.1~esm2 |
| gimp | gimp | >= 0 < 2.10.18-1ubuntu0.1+esm2 | 2.10.18-1ubuntu0.1+esm2 |
| gimp | gimp | >= 0 < 2.10.30-1ubuntu0.1+esm2 | 2.10.30-1ubuntu0.1+esm2 |
| gimp | gimp | >= 0 < 2.10.36-3ubuntu0.24.04.1+esm2 | 2.10.36-3ubuntu0.24.04.1+esm2 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
gimp vulnerabilities
osv·2026-03-04·CVSS 7.8
CVE-2025-2760 [HIGH] gimp vulnerabilities
gimp vulnerabilities
Michael Randrianantenaina discovered that calculating the linear size of a
DDS file could overflow on 32-bit systems. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04
LTS. (CVE-2025-2760)
Michael Randrianantenaina discovered that GIMP did not perform any bounds
checking when calculating an offset into XWD Colormaps. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2025-10934)
It was discovered that GIMP's PNM loader did not sufficiently check that
the image could fit within the allocated memory, which could cause GIMP to
read or write out-of-bounds. An attacker could possibly use this iss
OSV
CVE-2025-48798: A flaw was found in GIMP when processing XCF image files
osv·2025-05-27·CVSS 7.3
CVE-2025-48798 [HIGH] CVE-2025-48798: A flaw was found in GIMP when processing XCF image files
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
GHSA
GHSA-7p2h-v67m-x5qx: A flaw was found in GIMP when processing XCF image files
ghsa_unreviewed·2025-05-27
CVE-2025-48798 [HIGH] CWE-416 GHSA-7p2h-v67m-x5qx: A flaw was found in GIMP when processing XCF image files
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
Ubuntu
GIMP vulnerabilities
vendor_ubuntu·2026-03-04·CVSS 7.8
CVE-2025-48798 [HIGH] GIMP vulnerabilities
Title: GIMP vulnerabilities
Summary: Several security issues were fixed in GIMP.
Michael Randrianantenaina discovered that calculating the linear size of a
DDS file could overflow on 32-bit systems. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04
LTS. (CVE-2025-2760)
Michael Randrianantenaina discovered that GIMP did not perform any bounds
checking when calculating an offset into XWD Colormaps. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2025-10934)
It was discovered that GIMP's PNM loader did not sufficiently check that
the image could fit within the allocated memory, which could cause GIMP to
read or
Red Hat
gimp: Multiple use after free in XCF parser
vendor_redhat·2025-05-26·CVSS 7.3
CVE-2025-48798 [HIGH] CWE-416 gimp: Multiple use after free in XCF parser
gimp: Multiple use after free in XCF parser
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
Statement: This vulnerability in GIMP's XCF parser marked as Important rather than Moderate due to the nature and impact of the underlying memory management flaws—specifically, use-after-free and double-free condition
Debian
CVE-2025-48798: gimp - A flaw was found in GIMP when processing XCF image files. If a user opens one of...
vendor_debian·2025·CVSS 7.3
CVE-2025-48798 [HIGH] CVE-2025-48798: gimp - A flaw was found in GIMP when processing XCF image files. If a user opens one of...
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
Scope: local
bookworm: resolved (fixed in 2.10.34-1+deb12u3)
bullseye: resolved (fixed in 2.10.22-4+deb11u3)
forky: resolved (fixed in 3.0.0~RC1-4)
sid: resolved (fixed in 3.0.0~RC1-4)
trixie: resolved (fixed in 3.0.0~RC1-4)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2025:9162https://access.redhat.com/errata/RHSA-2025:9165https://access.redhat.com/errata/RHSA-2025:9308https://access.redhat.com/errata/RHSA-2025:9309https://access.redhat.com/errata/RHSA-2025:9310https://access.redhat.com/errata/RHSA-2025:9314https://access.redhat.com/errata/RHSA-2025:9315https://access.redhat.com/errata/RHSA-2025:9316https://access.redhat.com/errata/RHSA-2025:9501https://access.redhat.com/errata/RHSA-2025:9569https://access.redhat.com/security/cve/CVE-2025-48798https://bugzilla.redhat.com/show_bug.cgi?id=2368557https://gitlab.gnome.org/GNOME/gimp/-/issues/11822https://lists.debian.org/debian-lts-announce/2025/10/msg00022.html
2025-05-27
Published