GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability
Published Apr 11, 2026
7.8
HIGHCVSS 3.1
EPSS 0.52%
Description
GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of ANI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28813.
Affected products
-
- Version 3.0.8StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 9
gimp-2:3.0.4-1.el9_7.5
Fixed · RHSA-2026:16484
Red Hat Enterprise Linux 9
gimp-2:3.0.4-4.el9_8.4
Fixed · RHSA-2026:19362
Red Hat Enterprise Linux 6
gimp
Out of support scope
Red Hat Enterprise Linux 7
gimp
Not affected
Red Hat Enterprise Linux 8
gimp:2.8/gimp
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | gimp-2:3.0.4-1.el9_7.5 | Fixed | RHSA-2026:16484 |
| Red Hat Enterprise Linux 9 | gimp-2:3.0.4-4.el9_8.4 | Fixed | RHSA-2026:19362 |
| Red Hat Enterprise Linux 6 | gimp | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | gimp | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gimp:2.8/gimp | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Important: This flaw in GIMP allows for remote code execution due to an integer overflow when parsing specially crafted ANI (Animated Cursor) files. Exploitation requires user interaction, specifically opening a malicious ANI file or visiting a malicious web page. Red Hat users are affected if they process untrusted ANI files with GIMP.
Red Hat mitigation
To mitigate this issue, users should exercise caution and avoid opening untrusted ANI (Animated Cursor) files or visiting untrusted web pages. This vulnerability relies on user interaction to trigger the flaw, therefore, refraining from interacting with untrusted content will prevent exploitation.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Apr 13, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.52% (0.00518) | 41.94th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.59% (0.00592) | 43.47th | v5 (v2026.06.15) |
| Apr 11, 2026 | 0.06% (0.00063) | 19.65th | v4 (v2025.03.14) |
References (9)
- https://access.redhat.com/errata/RHSA-2026:16484
- https://access.redhat.com/errata/RHSA-2026:19362
- https://access.redhat.com/security/cve/CVE-2026-4151 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2457532 Issue Tracking
- https://gitlab.gnome.org/GNOME/gimp/-/commit/09e5459de913172fc51da3bd6b6adc533acd368e vendor-advisoryPatch
- https://nvd.nist.gov/vuln/detail/CVE-2026-4151
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4151.json
- https://www.cve.org/CVERecord?id=CVE-2026-4151
- https://www.zerodayinitiative.com/advisories/ZDI-26-218/ x_research-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.