CVE-2026-40918
published 2026-04-15CVE-2026-40918: A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.20%
9.6th percentile
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PVR image files are affected.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GIMP PVR Image buffer size
vuldb·2026-04-16·CVSS 5.5
CVE-2026-40918 [MEDIUM] GIMP PVR Image buffer size
A vulnerability identified as problematic has been detected in GIMP. This affects an unknown part of the component PVR Image Handler. The manipulation leads to incorrect calculation of buffer size.
This vulnerability is documented as CVE-2026-40918. The attack can be initiated remotely. There is not any exploit available.
GHSA
GHSA-qh6q-mfp5-q5wr: A flaw was found in GIMP
ghsa_unreviewed·2026-04-15
CVE-2026-40918 [MEDIUM] CWE-131 GHSA-qh6q-mfp5-q5wr: A flaw was found in GIMP
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PVR image files are affected.
Red Hat
gimp: GIMP: Denial of Service via crafted PVR image file
vendor_redhat·2026-04-15·CVSS 5.5
CVE-2026-40918 [MEDIUM] CWE-131 gimp: GIMP: Denial of Service via crafted PVR image file
gimp: GIMP: Denial of Service via crafted PVR image file
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PVR image files are affected.
Statement: This is a Moderate impact vulnerability. Processing a specially crafted PVR image file can lead to a denial of service due to a stack-based buffer overflow and out-of-bounds read in the PVR image loader. Systems that process untrusted PVR image files are affected. The impact may be limited if the PVR image loader is part of an optional component or plugin not enabled by default.
Mitigation: To redu
No detection rules found.
No public exploits indexed.
2026-04-15
Published