CVE-2026-40915
published 2026-04-15CVE-2026-40915: A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.38%
29.8th percentile
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data. Successful exploitation could result in a denial of service (DoS) or potentially arbitrary code execution.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GIMP integer overflow
vuldb·2026-04-16·CVSS 5.5
CVE-2026-40915 [MEDIUM] GIMP integer overflow
A vulnerability was found in GIMP. It has been declared as problematic. Affected is an unknown function. Such manipulation leads to integer overflow.
This vulnerability is listed as CVE-2026-40915. The attack may be performed from remote. There is no available exploit.
GHSA
GHSA-4f9g-vrx9-f8cq: A flaw was found in GIMP
ghsa_unreviewed·2026-04-15
CVE-2026-40915 [MEDIUM] CWE-190 GHSA-4f9g-vrx9-f8cq: A flaw was found in GIMP
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data. Successful exploitation could result in a denial of service (DoS) or potentially arbitrary code execution.
Red Hat
gimp: GIMP: Heap buffer overflow due to integer overflow in FITS image loader
vendor_redhat·2026-04-15·CVSS 5.5
CVE-2026-40915 [MEDIUM] CWE-190 gimp: GIMP: Heap buffer overflow due to integer overflow in FITS image loader
gimp: GIMP: Heap buffer overflow due to integer overflow in FITS image loader
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data. Successful exploitation could result in a denial of service (DoS) or potentially arbitrary code execution.
Statement: Moderate. This flaw in GIMP's FITS image loader could lead to a denial of service or arbitrary code execution when processing a specially crafted FITS file. Exploitation requires user interaction, as a malicious file must be opened by the application. Red Hat Enterprise Linux systems are affected if
No detection rules found.
No public exploits indexed.
2026-04-15
Published