Status: UPDATED
| Advisory ID: CVE-2026-90948
Key Details
| CVE | CVE-2026-90948 |
| CVSS Score / Version | 7.8 (High) / CVSS v3.1 |
| Updated | 2026-10-05 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, and Red Hat Enterprise Linux 7 |
| Classified as | CWE-787 (Out-of-bounds Write) |
Affected Products, Subsystems & Sectors
| Subsystems | OT Supporting Infrastructure |
| Sectors | Multiple |
What to Know
A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocated, causing a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by crafting a malicious ICO file, which, when opened, could lead to arbitrary code execution or a crash. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References