CVE-2026-2271
published 2026-03-26CVE-2026-2271: A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block()…
PriorityP425medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.49%
39.5th percentile
A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write. Successful exploitation could result in an application level denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.10.34-1+deb12u8 (bookworm) | gimp 2.10.34-1+deb12u8 (bookworm) |
| gimp | gimp | — | — |
| gimp | gimp | >= 0 < 2.10.22-4+deb11u6 | 2.10.22-4+deb11u6 |
| gimp | gimp | >= 0 < 2.10.34-1+deb12u8 | 2.10.34-1+deb12u8 |
| gimp | gimp | >= 0 < 3.0.4-3+deb13u6 | 3.0.4-3+deb13u6 |
| gimp | gimp | >= 0 < 3.2.0~RC2-3.2 | 3.2.0~RC2-3.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-688g-4qr3-6q47: A flaw was found in GIMP's PSP (Paint Shop Pro) file parser
ghsa_unreviewed·2026-03-26
CVE-2026-2271 [LOW] CWE-190 GHSA-688g-4qr3-6q47: A flaw was found in GIMP's PSP (Paint Shop Pro) file parser
A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write. Successful exploitation could result in an application level denial of service.
OSV
CVE-2026-2271: A flaw was found in GIMP's PSP (Paint Shop Pro) file parser
osv·2026-03-26·CVSS 3.3
CVE-2026-2271 [LOW] CVE-2026-2271: A flaw was found in GIMP's PSP (Paint Shop Pro) file parser
A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write. Successful exploitation could result in an application level denial of service.
Red Hat
gimp: GIMP: Denial of service via crafted PSP image file
vendor_redhat·2026-02-10·CVSS 3.3
CVE-2026-2271 [LOW] CWE-190 gimp: GIMP: Denial of service via crafted PSP image file
gimp: GIMP: Denial of service via crafted PSP image file
A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write. Successful exploitation could result in an application level denial of service.
A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value fro
Debian
CVE-2026-2271: gimp - A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker c...
vendor_debian·2026·CVSS 3.3
CVE-2026-2271 [LOW] CVE-2026-2271: gimp - A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker c...
A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write. Successful exploitation could result in an application level denial of service.
Scope: local
bookworm: resolved (fixed in 2.10.34-1+deb12u8)
bullseye: resolved (fixed in 2.10.22-4+deb11u6)
forky: resolved (fixed in 3.2.0~RC2-3.2)
sid: resolved (fixed in 3.2.0~RC2-3.2)
trixie: resolved (fixed in 3.0.4-3+deb13u6)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-2271 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-2271 [LOW] CVE-2026-2271 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2271 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write. Successful exploitation could result in an application level denial of service.
Source : NVD
## 3.3
Score
Published March 26, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probab
Bugzilla
CVE-2026-2271 gimp: GIMP: Denial of service via crafted PSP image file
bugzilla·2026-02-10·CVSS 5.5
CVE-2026-2271 [MEDIUM] CVE-2026-2271 gimp: GIMP: Denial of service via crafted PSP image file
CVE-2026-2271 gimp: GIMP: Denial of service via crafted PSP image file
An integer overflow vulnerability has been identified in the PSP (Paint Shop Pro) file parser of GIMP. The issue occurs in the read_creator_block() function, where the Creator metadata block is processed. Specifically, a 32-bit length value read from the file is used directly for memory allocation without proper validation.
Trigger -> when length is set to 0xFFFFFFFF
g_malloc(0xFFFFFFFF + 1) results in g_malloc(0), leading to the allocation of a minimal-sized buffer
fread() then attempts to read approximately 4 GB of data into this small buffer
Writing string[0xFFFFFFFF] = '\0' causes an out-of-bounds write beyond the allocated buffer
Vulnerable code (file-psp.c:1130):
guint32 length;
fread(&length, 4, 1, f); // Re
2026-03-26
Published