Gimp: gimp:memory disclosure and denial of service via specially crafted pcx image
Published Mar 26, 2026
7.1
HIGHCVSS 3.1
EPSS 0.55%
Description
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
Affected products
No data.
Running on/with
- 6.0
- 7.0
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
gimp-2:2.8.22-1.el7_9.6
Fixed · RHSA-2026:26168
Red Hat Enterprise Linux 8
gimp:2.8-8100020260512115927.4c9c024f
Fixed · RHSA-2026:17533
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
gimp:2.8-8040020260520140422.70584597
Fixed · RHSA-2026:20552
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
gimp:2.8-8040020260520140422.70584597
Fixed · RHSA-2026:20552
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
gimp:2.8-8060020260520140100.6af1eaf0
Fixed · RHSA-2026:20553
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
gimp:2.8-8060020260520140100.6af1eaf0
Fixed · RHSA-2026:20553
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
gimp:2.8-8060020260520140100.6af1eaf0
Fixed · RHSA-2026:20553
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
gimp:2.8-8080020260520102644.0621e4ee
Fixed · RHSA-2026:20554
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
gimp:2.8-8080020260520102644.0621e4ee
Fixed · RHSA-2026:20554
Red Hat Enterprise Linux 9
gimp-2:3.0.4-1.el9_7.5
Fixed · RHSA-2026:16484
Red Hat Enterprise Linux 9
gimp-2:3.0.4-4.el9_8.4
Fixed · RHSA-2026:19362
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
gimp-2:2.99.8-3.el9_0.6
Fixed · RHSA-2026:20691
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
gimp-2:2.99.8-4.el9_2.6
Fixed · RHSA-2026:25899
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
gimp-2:2.99.8-4.el9_4.6
Fixed · RHSA-2026:25907
Red Hat Enterprise Linux 9.6 Extended Update Support
gimp-2:2.99.8-4.el9_6.7
Fixed · RHSA-2026:25901
Red Hat Enterprise Linux 6
gimp
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | gimp-2:2.8.22-1.el7_9.6 | Fixed | RHSA-2026:26168 |
| Red Hat Enterprise Linux 8 | gimp:2.8-8100020260512115927.4c9c024f | Fixed | RHSA-2026:17533 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gimp:2.8-8040020260520140422.70584597 | Fixed | RHSA-2026:20552 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | gimp:2.8-8040020260520140422.70584597 | Fixed | RHSA-2026:20552 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | gimp:2.8-8060020260520140100.6af1eaf0 | Fixed | RHSA-2026:20553 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | gimp:2.8-8060020260520140100.6af1eaf0 | Fixed | RHSA-2026:20553 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | gimp:2.8-8060020260520140100.6af1eaf0 | Fixed | RHSA-2026:20553 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | gimp:2.8-8080020260520102644.0621e4ee | Fixed | RHSA-2026:20554 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | gimp:2.8-8080020260520102644.0621e4ee | Fixed | RHSA-2026:20554 |
| Red Hat Enterprise Linux 9 | gimp-2:3.0.4-1.el9_7.5 | Fixed | RHSA-2026:16484 |
| Red Hat Enterprise Linux 9 | gimp-2:3.0.4-4.el9_8.4 | Fixed | RHSA-2026:19362 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | gimp-2:2.99.8-3.el9_0.6 | Fixed | RHSA-2026:20691 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | gimp-2:2.99.8-4.el9_2.6 | Fixed | RHSA-2026:25899 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | gimp-2:2.99.8-4.el9_4.6 | Fixed | RHSA-2026:25907 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | gimp-2:2.99.8-4.el9_6.7 | Fixed | RHSA-2026:25901 |
| Red Hat Enterprise Linux 6 | gimp | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Users should avoid opening untrusted PCX image files with GIMP. If GIMP is not required, consider removing the `gimp` package to eliminate this attack vector.
Red Hat statement
Moderate: This flaw in GIMP's PCX file loader is due to a heap buffer over-read. Exploitation requires user interaction, specifically opening a specially crafted PCX image file. Red Hat Enterprise Linux systems are affected if GIMP is installed and used to open untrusted PCX files.
Red Hat mitigation
Users should avoid opening untrusted PCX image files with GIMP. If GIMP is not required, consider removing the `gimp` package to eliminate this attack vector.
References (17)
- https://access.redhat.com/errata/RHSA-2026:16484 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:17533 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19362 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:20552 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:20553 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:20554 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:20691 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25899 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25901 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25907 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:26168 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-4887 vdb-entryx_refsource_REDHATMitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2451669 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16166 Advisory
- https://gitlab.gnome.org/GNOME/gimp/-/issues/15960 ExploitIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-4887
- https://www.cve.org/CVERecord?id=CVE-2026-4887
Change history (0)
No recorded changes yet.