CVE-2026-40915: Gimp: gimp: heap buffer overflow due to integer overflow in fits image loader
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data. Successful exploitation could result in a denial of service (DoS) or potentially arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40915?
CVE-2026-40915 is considered a high-severity vulnerability due to its potential for exploitation through specially crafted FITS files.
How do I fix CVE-2026-40915?
To fix CVE-2026-40915, update GIMP to the latest version that addresses the integer overflow vulnerability in the FITS image loader.
What type of vulnerability is CVE-2026-40915?
CVE-2026-40915 is a heap buffer overflow vulnerability caused by an integer overflow in the FITS image loader.
Who could exploit CVE-2026-40915?
A remote attacker could exploit CVE-2026-40915 by uploading a specially crafted FITS file to trigger the vulnerability.
What are the potential impacts of CVE-2026-40915?
The potential impacts of CVE-2026-40915 include unauthorized access and execution of arbitrary code on affected systems.