Skip to content
Red HatCVE-2026-90947

Red Hat GIMP.: out-of-bounds write

High7.8CVE-2026-90947 · Published Sep 14, 2026 · updated Sep 17, 2026

A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to open a malicious preset file, potentially causing a crash or enabling arbitrary code execution.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat sssd: out-of-bounds read
Medium4.0Sep 14
Red Hat Enterprise Linux 10: null pointer dereference
Medium5.5Sep 14
Red Hat sssd. A local unprivileged user: denial of service
Medium4.0Sep 14
Red Hat sssd NSS responder: out-of-bounds read
Medium4.0Sep 14
Red Hat GIMP: integer overflow
High7.8Sep 14
Red Hat GIMP: heap buffer overflow
High7.8Sep 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.