7.8
CVE-2026-58380
- EPSS 0.26%
- Veröffentlicht 06.07.2026 13:58:43
- Zuletzt bearbeitet 30.09.2026 15:22:31
- Erkennungen
Gimp: gimp: stack buffer overflow in pnmscanner_gettoken()
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.173 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| RedHat | 7.3 | 1.3 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-193 Off-by-one Error
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
https://bugzilla.redhat.com/show_bug.cgi?id=2496135
https://access.redhat.com/security/cve/CVE-2026-58380
https://gitlab.gnome.org/GNOME/gimp/-/commit/83699817
https://gitlab.gnome.org/GNOME/gimp/-/issues/16206
https://access.redhat.com/errata/RHSA-2026:40751
https://access.redhat.com/errata/RHSA-2026:62507
https://access.redhat.com/errata/RHSA-2026:73768