Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-97185EXPLOITED
red hat · red hat enterprise linux

Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file

Description

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourceopen source gimpcert_advisory90%

References

  • https://access.redhat.com/security/cve/CVE-2026-97185(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2539980(issue-tracking, x_refsource_REDHAT)
  • https://gitlab.gnome.org/GNOME/gimp/-/work_items/16788

Related News (2 articles)

Tier B
BSI Advisories2d ago
[NEU] [mittel] GIMP: Schwachstelle ermöglicht Codeausführung und Denial of Service
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-97185 | GIMP GIMPressionist out-of-bounds write
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.8 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-787
PublishedSep 24, 2026
Last enriched3d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score36
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-96280EXP
Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems
Trending: 46
MEDIUMCVE-2026-96281EXP
Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes
Trending: 42
LOWCVE-2026-96284EXP
Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following
Trending: 40
NONECVE-2026-88924EXP
Gvfs: gvfs-admin socket ownership race permits local root
Trending: 36
NONECVE-2026-96546EXP
Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader
Trending: 34

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 24, 2026
Discovered by ZDM
Sep 24, 2026
Actively Exploited
Sep 24, 2026
Exploit Available
Sep 24, 2026