Skip to content
Red HatCVE-2026-90948

Red Hat GIMP: integer overflow

High7.8CVE-2026-90948 · Published Sep 14, 2026 · updated Sep 16, 2026

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocated, causing a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by crafting a malicious ICO file, which, when opened, could lead to arbitrary code execution or a crash.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat sssd: out-of-bounds read
Medium4.0Sep 14
Red Hat Enterprise Linux 10: null pointer dereference
Medium5.5Sep 14
Red Hat sssd. A local unprivileged user: denial of service
Medium4.0Sep 14
Red Hat GIMP.: out-of-bounds write
High7.8Sep 14
Red Hat sssd NSS responder: out-of-bounds read
Medium4.0Sep 14
Red Hat GIMP: heap buffer overflow
High7.8Sep 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.