CVE-2026-58380
published 2026-07-06CVE-2026-58380: A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.22%
12.1th percentile
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gimp | gimp | — | — |
| gimp | gimp | — | — |
| gimp_2.8 | gimp | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gimp: gimp: Stack buffer overflow in pnmscanner_gettoken()
vendor_redhat·2026-04-11·CVSS 7.3
CVE-2026-58380 [HIGH] CWE-193 gimp: gimp: Stack buffer overflow in pnmscanner_gettoken()
gimp: gimp: Stack buffer overflow in pnmscanner_gettoken()
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
Statement: This Moderate flaw in GIMP's PNM file parser could lead to memory corruption and potentially arbitrary code execution or denial of service. The vulnerability requires a user to open a specially crafted PNM image file with GIMP. As a desktop application, the impact is limited to the user's session and requires user interaction.
Mitigation: None — requires o
GHSA
A flaw was found in GIMP's PNM file format parser.
ghsa_unreviewed·2026-07-06
CVE-2026-58380 [HIGH] CWE-193 A flaw was found in GIMP's PNM file format parser.
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
No detection rules found.
No public exploits indexed.
2026-07-06
Published