← All Advisories

CVE-2026-58380

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-58380

Key Details

CVECVE-2026-58380
CVSS Score / Version7.3 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-193 (Off-by-one Error)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat Enterprise Linux 7
gimpgimp
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. (NVD)

What to Do

Monitor Red Hat's and gimp's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-58380
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-58380
Vendor advisoryhttps://gitlab.gnome.org/GNOME/gimp/-/issues/16206