CVE-2026-108093: Gimp: gimp: denial of service via null pointer dereference in xcf simulation parasite loading
A flaw was found in GIMP. The XCF loader processes image-simulation-intent and image-simulation-bpc parasites without ensuring the parasite data is present before dereferencing it. Opening a specially crafted XCF file with a zero-size simulation parasite can cause a NULL pointer dereference and crash the GIMP application.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of GIMP who open untrusted or specially crafted XCF image files are exposed. The reported impact is a crash of the GIMP application rather than loss of confidentiality or integrity.
What does an attacker need to exploit it?
An attacker needs to provide a specially crafted XCF file containing a zero-size image-simulation-intent or image-simulation-bpc parasite and convince a user to open it in GIMP. No privileges are required, but user interaction is required.
How can I tell whether an XCF file is malicious for this issue?
The triggering condition described is a zero-size image-simulation-intent or image-simulation-bpc parasite in an XCF file. Opening such a file may cause GIMP to crash due to a NULL pointer dereference.