Status: UPDATED
| Advisory ID: CVE-2026-58380
Key Details
| CVE | CVE-2026-58380 |
| CVSS Score / Version | 7.3 (High) / CVSS v3.1 |
| Updated | 2026-09-30 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | see table below |
| Classified as | CWE-193 (Off-by-one Error) |
Affected Products, Subsystems & Sectors
| Subsystems | OT Supporting Infrastructure |
| Sectors | All Sectors |
What to Know
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. (NVD)
What to Do
Monitor Red Hat's and gimp's web pages for any future patch releases. See vendor advisory link below.
References