CVE-2026-40917: Gimp: gimp: application crashes or information disclosure via crafted icns image files
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the icnsslurp() function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40917?
CVE-2026-40917 is classified as a medium severity vulnerability due to the potential for application crashes or information disclosure.
How do I fix CVE-2026-40917?
To fix CVE-2026-40917, ensure you update GIMP to the latest version where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-40917?
CVE-2026-40917 is a heap buffer over-read vulnerability affecting the 'icns_slurp()' function in GIMP.
What impact does CVE-2026-40917 have on GIMP users?
If exploited, CVE-2026-40917 could lead to application crashes or allow attackers to disclose sensitive information through crafted ICNS files.
Which versions of GIMP are affected by CVE-2026-40917?
CVE-2026-40917 affects specific versions of GIMP that process ICNS image files without appropriate validation.