HIGH 7.8 NVD
CVE-2026-92248
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer ove
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution.
References
- https://access.redhat.com/security/cve/CVE-2026-92248
- https://bugzilla.redhat.com/show_bug.cgi?id=2534282
- https://gitlab.gnome.org/GNOME/gimp/-/work_items/16775
This high severity vulnerability with a CVSS score of 7.8 was published on 2026-09-15 via NVD.
vulnfeed aggregates 14340 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.