Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4989 articles · 189008 vulns · 37/41 feeds (7d)
← Back to list
5.5
CVE-2026-59088EXPLOITED
red hat · red hat enterprise linux

Gimp: gimp: denial of service via signed integer overflow in fli file processing

Description

A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the multiplication of image width and height can exceed the maximum integer value. A remote attacker could exploit this by tricking a user into opening a specially crafted FLI file, leading to the application crashing and resulting in a denial of service.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcegimpcert_advisory90%

References

  • https://access.redhat.com/security/cve/CVE-2026-59088(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2496582(issue-tracking, x_refsource_REDHAT)
  • https://gitlab.gnome.org/GNOME/gimp/-/work_items/16492

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [hoch] GIMP: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB2d ago
CVE-2026-59088 | GIMP file-fli integer overflow
→ No new info (linked only)
CVSS 3.15.5 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-190
PublishedAug 10, 2026
Last enriched2d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score43
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-4480EXPKEV
Samba: samba: remote code execution in printing subsystem via unescaped job description
Trending: 48
NONECVE-2026-59091EXP
Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file
Trending: 47
MEDIUMCVE-2026-6426EXP
Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access
Trending: 45
NONECVE-2026-59090EXP
Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
Trending: 44
LOWCVE-2026-61477EXP
Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection
Trending: 43

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026
Actively Exploited
Aug 11, 2026
Exploit Available
Aug 11, 2026