CVE-2025-5473
published 2025-06-06CVE-2025-5473: GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected…
PriorityP264high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
12.51%
95.8th percentile
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26752.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.10.34-1+deb12u3 (bookworm) | gimp 2.10.34-1+deb12u3 (bookworm) |
| gimp | gimp | < 3.0.4 | 3.0.4 |
| gimp | gimp | — | — |
| gimp | gimp | >= 0 < 2.10.22-4+deb11u3 | 2.10.22-4+deb11u3 |
| gimp | gimp | >= 0 < 2.10.34-1+deb12u3 | 2.10.34-1+deb12u3 |
| gimp | gimp | >= 0 < 3.0.2-3.1 | 3.0.2-3.1 |
| gimp | gimp | >= 0 < 3.0.2-3.1 | 3.0.2-3.1 |
| gimp | gimp | >= 0 < 2.8.16-1ubuntu1.1+esm3 | 2.8.16-1ubuntu1.1+esm3 |
| gimp | gimp | >= 0 < 2.8.22-1ubuntu0.1~esm3 | 2.8.22-1ubuntu0.1~esm3 |
| gimp | gimp | >= 0 < 2.10.18-1ubuntu0.1+esm3 | 2.10.18-1ubuntu0.1+esm3 |
| gimp | gimp | >= 0 < 2.10.30-1ubuntu0.1+esm3 | 2.10.30-1ubuntu0.1+esm3 |
| gimp | gimp | >= 0 < 2.10.36-3ubuntu0.24.04.1+esm3 | 2.10.36-3ubuntu0.24.04.1+esm3 |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger vector is a maliciously crafted ICO file opened by a GIMP user; hunt for GIMP processes loading unexpected or externally-sourced .ico files. ↗
- →User interaction is required — phishing or drive-by delivery of a malicious ICO file is the expected initial access path; monitor for GIMP launched with ICO file arguments from browser download directories or email attachment staging paths. ↗
- →Exploitation results in arbitrary code execution within the GIMP process context; monitor for anomalous child processes or network connections spawned by the gimp process after opening an ICO file. ↗
- →ZDI tracking ID ZDI-CAN-26752 can be used to cross-reference any future PoC or exploit code releases associated with this vulnerability. ↗
- ·The NVD/ZDI advisory describes a remote attack vector, but Red Hat's analysis indicates remote exploitation is not possible in their software stack; treat attack vector as local/social-engineering (malicious file open) rather than network-reachable. ↗
- ·GIMP on Red Hat Enterprise Linux 6 is out of support scope — no patch will be issued for that platform; patched versions exist for Debian (bookworm: 2.10.34-1+deb12u3, bullseye: 2.10.22-4+deb11u3, trixie/forky/sid: 3.0.2-3.1) and Ubuntu (via USN-8082-1). ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GIMP vulnerabilities
vendor_ubuntu·2026-03-10·CVSS 8.8
CVE-2025-6035 [HIGH] GIMP vulnerabilities
Title: GIMP vulnerabilities
Summary: Several security issues were fixed in GIMP.
Michael Randrianantenaina discovered that GIMP incorrectly handled certain
malformed ICO files. An attacker could possibly use this to cause a denial
of service or execute arbitrary code. (CVE-2025-5473)
Seungho Kim discovered that GIMP incorrectly handled certain memory
operations when running the despeckle plugin. An attacker could possibly
use this to cause a denial of service or execute arbitrary code.
(CVE-2025-6035)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gimp: GIMP ICO File Parsing Integer Overflow
vendor_redhat·2025-06-06·CVSS 8.8
CVE-2025-5473 [HIGH] CWE-190 gimp: GIMP ICO File Parsing Integer Overflow
gimp: GIMP ICO File Parsing Integer Overflow
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26752.
An integer overflow vulnerability was found in Gimp's handling of ICO files. This vulnerability can lead to code execution
Red Hat
kernel: HID: ignore non-functional sensor in HP 5MP Camera
vendor_redhat·2025-04-02·CVSS 5.5
CVE-2025-21992 [MEDIUM] CWE-20 kernel: HID: ignore non-functional sensor in HP 5MP Camera
kernel: HID: ignore non-functional sensor in HP 5MP Camera
In the Linux kernel, the following vulnerability has been resolved:
HID: ignore non-functional sensor in HP 5MP Camera
The HP 5MP Camera (USB ID 0408:5473) reports a HID sensor interface that
is not actually implemented. Attempting to access this non-functional
sensor via iio_info causes system hangs as runtime PM tries to wake up
an unresponsive sensor.
[453] hid-sensor-hub 0003:0408:5473.0003: Report latency attributes: ffffffff:ffffffff
[453] hid-sensor-hub 0003:0408:5473.0003: common attributes: 5:1, 2:1, 3:1 ffffffff:ffffffff
Add this device to the HID ignore list since the sensor interface is
non-functional by design and should not be exposed to userspace.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Packag
Debian
CVE-2025-5473: gimp - GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This...
vendor_debian·2025·CVSS 8.8
CVE-2025-5473 [HIGH] CVE-2025-5473: gimp - GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This...
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26752.
Scope: local
bookworm: resolved (fixed in 2.10.34-1+deb12u3)
bullseye: resolved (fixed in 2.10.22-4+deb11u3)
forky: resolved (fixed in 3.0.2-3.1)
sid: resolved (fixed in
OSV
gimp vulnerabilities
osv·2026-03-10·CVSS 8.8
CVE-2025-5473 [HIGH] gimp vulnerabilities
gimp vulnerabilities
Michael Randrianantenaina discovered that GIMP incorrectly handled certain
malformed ICO files. An attacker could possibly use this to cause a denial
of service or execute arbitrary code. (CVE-2025-5473)
Seungho Kim discovered that GIMP incorrectly handled certain memory
operations when running the despeckle plugin. An attacker could possibly
use this to cause a denial of service or execute arbitrary code.
(CVE-2025-6035)
GHSA
GHSA-23w7-3gw5-5jqr: GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability
ghsa_unreviewed·2025-06-06
CVE-2025-5473 [HIGH] CWE-190 GHSA-23w7-3gw5-5jqr: GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26752.
OSV
CVE-2025-5473: GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability
osv·2025-06-06·CVSS 8.8
CVE-2025-5473 [HIGH] CVE-2025-5473: GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26752.
No detection rules found.
No public exploits indexed.
2025-06-06
Published