Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
8.4
CVE-2026-59090EXPLOITED
red hat · red hat enterprise linux

Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow

Description

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcegimpcert_advisory90%

References

  • https://access.redhat.com/security/cve/CVE-2026-59090(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2496584(issue-tracking, x_refsource_REDHAT)
  • https://gitlab.gnome.org/GNOME/gimp/-/work_items/16509

Related News (1 articles)

Tier B
BSI Advisories1d ago
[NEU] [hoch] GIMP: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.18.4 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-191
PublishedAug 10, 2026
Last enriched2d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score44
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-4480EXPKEV
Samba: samba: remote code execution in printing subsystem via unescaped job description
Trending: 49
NONECVE-2026-59091EXP
Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file
Trending: 47
MEDIUMCVE-2026-6426EXP
Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access
Trending: 45
NONECVE-2026-63623EXP
Libvirt: information disclosure via world-readable storage volume images during clone/convert
Trending: 43
NONECVE-2026-59088EXP
Gimp: gimp: denial of service via signed integer overflow in fli file processing
Trending: 43

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026
Actively Exploited
Aug 12, 2026
Exploit Available
Aug 12, 2026