CVE-2026-2239Patch(gimp / enterprise_linux)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gimp enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an out-of-bounds read when strlen() is subsequently called. Successfully exploiting this vulnerability can cause the application to crash, resulting in an application level Denial of Service.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-170

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • gimp

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-01); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
enterprise_linuxgimp

4 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-01: 1Mentions · 2026-03-06: 1Mentions · 2026-03-26: 1Patch / Workaround · 2026-03-01: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-26: 103-0103-0603-26
Signal classification3 categories
Patch
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-011
Patch1
2026-03-061
General1
2026-03-261
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2239 A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) fil… https://www.cve.org/CVERecord?id=CVE-2026-2239

    Post summary

    A heap‑buffer‑overflow vulnerability was disclosed in GIMP’s fread_pascal_string function when parsing specially crafted Photoshop Document files.

    00000109
    56.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-2239 GIMP https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2239 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet merely names CVE-2026-2239 for GIMP and links to a vulnerability detail page, offering no substantive information beyond the identifier.

    0000033
    4.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security advisory for #Fedora 43: GIMP 3.0.8-5 fixes CVE-2026-2239, a heap-buffer-overflow in the PSD loader. This is a DoS vector using crafted PSDs. Read more: 👉 https://tinyurl.com/2tks99p8 #Security https://t.co/ajwNQUnT4D

    Post summary

    The advisory announces that Fedora 43’s GIMP 3.0.8-5 patch resolves CVE-2026-2239, a heap‑buffer‑overflow in the PSD loader that could lead to denial‑of‑service via crafted PSD files.

    0000073
    1.3K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appgimpgimp3.2.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more