7.3

CVE-2026-58381

Gimp: gimp: double-free in read_layer_block()

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gimp ≫ Gimp Version <= 3.2.1
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.02
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
RedHat 6.1 1.3 4.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H
CWE-415 Double Free

The product calls free() twice on the same memory address.

https://bugzilla.redhat.com/show_bug.cgi?id=2496166
Vendor Advisory
Issue Tracking
https://access.redhat.com/security/cve/CVE-2026-58381
Vendor Advisory
https://gitlab.gnome.org/GNOME/gimp/-/commit/b22e147b
Patch
https://gitlab.gnome.org/GNOME/gimp/-/issues/16207
Vendor Advisory
Issue Tracking