CVE-2026-58384
published 2026-07-07CVE-2026-58384: A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.22%
12.4th percentile
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gimp | gimp | — | — |
| gimp | gimp | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gimp: gimp: Integer overflow in read_RLE_channel()
vendor_redhat·2026-04-11·CVSS 7.3
CVE-2026-58384 [HIGH] CWE-190 gimp: gimp: Integer overflow in read_RLE_channel()
gimp: gimp: Integer overflow in read_RLE_channel()
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
Statement: A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can make the RLE row-length allocation too small and lead to heap memory corruption during subsequent row processing. Successful exploitation requires a user to open a specially crafted PSD file.
Mitigation: None — requires opening a crafted PSD file.
Package: gimp (Red Hat Enterprise Linux 6) - Not affected
Package: gimp (Red Hat
VulDB
GIMP PSD Parser read_RLE_channel integer overflow (Nessus ID 327524)
vuldb·2026-07-18·CVSS 7.8
CVE-2026-58384 [HIGH] GIMP PSD Parser read_RLE_channel integer overflow (Nessus ID 327524)
A vulnerability was found in GIMP. It has been declared as critical. This affects the function read_RLE_channel of the component PSD Parser. The manipulation results in integer overflow.
This vulnerability is known as CVE-2026-58384. It is possible to launch the attack remotely. No exploit is available.
GHSA
A flaw was found in GIMP's PSD parser.
ghsa_unreviewed·2026-07-07
CVE-2026-58384 [HIGH] CWE-190 A flaw was found in GIMP's PSD parser.
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
No detection rules found.
No public exploits indexed.
2026-07-07
Published