CVE-2026-4887
published 2026-03-26CVE-2026-4887: A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by…
PriorityP430high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.63%
46.7th percentile
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 3.2.0-1 (forky) | gimp 3.2.0-1 (forky) |
| gimp | gimp | < 3.2.0 | 3.2.0 |
| gimp | gimp | — | — |
| gimp | gimp | — | — |
| gimp | gimp | — | — |
| gimp | gimp | >= 0 < 3.2.0-1 | 3.2.0-1 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GIMP PCX File Loader off-by-one (Nessus ID 303830 / WID-SEC-2026-0882)
vuldb·2026-05-17·CVSS 7.1
CVE-2026-4887 [HIGH] GIMP PCX File Loader off-by-one (Nessus ID 303830 / WID-SEC-2026-0882)
A vulnerability was found in GIMP. It has been classified as problematic. Impacted is an unknown function of the component PCX File Loader. Performing a manipulation results in off-by-one.
This vulnerability is cataloged as CVE-2026-4887. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
GHSA-wmqx-rmqw-vxp8: A flaw was found in GIMP
ghsa_unreviewed·2026-03-26
CVE-2026-4887 [MEDIUM] CWE-193 GHSA-wmqx-rmqw-vxp8: A flaw was found in GIMP
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
OSV
CVE-2026-4887: A flaw was found in GIMP
osv·2026-03-26·CVSS 6.1
CVE-2026-4887 [MEDIUM] CVE-2026-4887: A flaw was found in GIMP
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
Red Hat
gimp: GIMP:Memory disclosure and denial of service via specially crafted PCX image
vendor_redhat·2026-03-26·CVSS 6.1
CVE-2026-4887 [MEDIUM] CWE-193 gimp: GIMP:Memory disclosure and denial of service via specially crafted PCX image
gimp: GIMP:Memory disclosure and denial of service via specially crafted PCX image
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
Debian
CVE-2026-4887: gimp - A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file...
vendor_debian·2026·CVSS 6.1
CVE-2026-4887 [MEDIUM] CVE-2026-4887: gimp - A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file...
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.2.0-1)
sid: resolved (fixed in 3.2.0-1)
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-4887 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-4887 [MEDIUM] CVE-2026-4887 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4887 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
Source : NVD
## 6.1
Score
Published March 26, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 24.9
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
gimp-devel
Bugzilla
CVE-2026-4887 gimp: GIMP:Memory disclosure and denial of service via specially crafted PCX image
bugzilla·2026-03-26·CVSS 6.1
CVE-2026-4887 [MEDIUM] CVE-2026-4887 gimp: GIMP:Memory disclosure and denial of service via specially crafted PCX image
CVE-2026-4887 gimp: GIMP:Memory disclosure and denial of service via specially crafted PCX image
This issue is a heap buffer over-read in GIMP’s PCX file loader due to an off‑by‑one error in the bytesperline validation logic. A specially crafted PCX image can cause GIMP to read beyond the bounds of a heap buffer when opened, leading to out‑of‑bounds memory disclosure and possible crash. Exploitation requires user interaction (opening a malicious PCX file)
https://access.redhat.com/errata/RHSA-2026:16484https://access.redhat.com/errata/RHSA-2026:17533https://access.redhat.com/errata/RHSA-2026:19362https://access.redhat.com/errata/RHSA-2026:20552https://access.redhat.com/errata/RHSA-2026:20553https://access.redhat.com/errata/RHSA-2026:20554https://access.redhat.com/errata/RHSA-2026:20691https://access.redhat.com/errata/RHSA-2026:25899https://access.redhat.com/errata/RHSA-2026:25901https://access.redhat.com/errata/RHSA-2026:25907https://access.redhat.com/security/cve/CVE-2026-4887https://bugzilla.redhat.com/show_bug.cgi?id=2451669https://gitlab.gnome.org/GNOME/gimp/-/issues/15960
2026-03-26
Published