CVE-2026-59090Disclosure(gimp / enterprise_linux)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch gimp enterprise_linux systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-191

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • gimp

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-10); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
enterprise_linuxgimp

4 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-08-10: 2Mentions · 2026-08-20: 1Mentions · 2026-09-01: 2PoC Mentioned / Linked · 2026-09-01: 2Patch / Workaround · 2026-09-01: 1Technical Details · 2026-08-10: 2Technical Details · 2026-08-20: 1Technical Details · 2026-09-01: 208-1008-2009-01
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-102
Disclosure2
2026-08-201
Disclosure1
2026-09-012
Disclosure1Patch1
Full discourse5 posts
  • takenaka hiroya@Joe_Biden_ja
    Patch

    GIMP の PSD プラグインに符号なし整数アンダーフロー。細工した .psd を開くと任意コード実行に至ります。見落としやすいのはヘッドレス経路で、画像変換パイプラインに入れていると操作なしでパーサへ届きます。RHEL は RHSA-2026:61587。 https://cve.autoarticles.net/cve/CVE-2026-59090

    Post summary

    The post details an unsigned integer underflow in GIMP’s PSD plugin that enables arbitrary code execution, notes a headless pipeline access path, and references the RHEL advisory RHSA‑2026:61587 along with a link to the CVE description.

    00000233
    556 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    残りバイト数を符号なし整数で持つと、引きすぎたときに 0 を下回らず最大値へ回り込みます。GIMP CVE-2026-59090 はこれで .psd のパーサが読み進めてしまう脆弱性。Node.js で同じ形を再現して、検査を引く前に置く必要がある理由を確かめました。 https://blog.hashito.biz/2026/09/01/gimp-cve-2026-59090-unsigned-integer-underflow-psd/

    Post summary

    The post discloses a GIMP vulnerability (CVE‑2026‑59090) involving an unsigned integer underflow in the PSD parser, demonstrates the issue in Node.js, and links to a blog article containing further details.

    0000076
    556 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 GIMP, Unsigned Integer Underflow, #CVE-2026-59090 (Critical) -DC-Aug2026-1668 https://dailycve.com/gimp-unsigned-integer-underflow-cve-2026-59090-critical-dc-aug2026-1668/

    Post summary

    The text announces a new critical unsigned integer underflow vulnerability in GIMP (CVE-2026-59090) but does not provide details about PoC, exploitation, or remediation.

    0000036
    229 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59090 A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially… https://www.cve.org/CVERecord?id=CVE-2026-59090 ----- Traducción: Se encontró una fa… http://infoflow.cloud`

    Post summary

    A new CVE has been disclosed: GIMP's PSD plugin contains an unsigned integer underflow in the `block_rem` variable; no exploit or patch details are provided yet.

    0000045
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-59090 A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially… https://www.cve.org/CVERecord?id=CVE-2026-59090

    Post summary

    The text reports a newly discovered unsigned integer underflow flaw in GIMP's PSD file plugin, providing a brief technical description but no evidence of exploitation, PoC, or mitigation.

    000001.5K
    57.9K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appgimpgimp3.3.1--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more