CVE-2026-40916
published 2026-04-15CVE-2026-40916: A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service…
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.21%
11.4th percentile
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-length array.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gimp: GIMP: Denial of Service due to stack buffer overflow in TIM image loader
vendor_redhat·2026-04-15·CVSS 5.0
CVE-2026-40916 [MEDIUM] CWE-787 gimp: GIMP: Denial of Service due to stack buffer overflow in TIM image loader
gimp: GIMP: Denial of Service due to stack buffer overflow in TIM image loader
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-length array.
Statement: This flaw has a Moderate impact. This vulnerability in GIMP's TIM image loader requires a local user to open a specially crafted TIM image file, leading to a denial of service. Red Hat Enterprise Linux systems are affected if GIMP is installed and used to process untrusted image files.
Mitigation: To mitigate this issue, users should avoid opening untrusted TIM image files with GIMP. As a gener
VulDB
GIMP TIM Image out-of-bounds write
vuldb·2026-04-16·CVSS 5.0
CVE-2026-40916 [MEDIUM] GIMP TIM Image out-of-bounds write
A vulnerability labeled as critical has been found in GIMP. The affected element is an unknown function of the component TIM Image Handler. Such manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2026-40916. The attack can be executed remotely. There is not any exploit available.
GHSA
GHSA-xcqw-9mv2-wqj3: A flaw was found in GIMP
ghsa_unreviewed·2026-04-15
CVE-2026-40916 [MEDIUM] CWE-787 GHSA-xcqw-9mv2-wqj3: A flaw was found in GIMP
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-length array.
No detection rules found.
No public exploits indexed.
2026-04-15
Published