CVE-2026-97185

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-24: 109-24
Referenced assets1 URL
By indicator
Full discourse1 post
  • VulnTracker@vuln_tracker

    A malicious GIMP preset file can crash your session or run attacker code (CVSS 7.8). Update to the patched version. Details: https://vulntracker.io/cves/CVE-2026-97185 #GIMP #CVE #RedHat #InfoSec #CyberSecurity https://t.co/2SCI8cBLZX

    00021119
    765 followersView on X

Explore more