REDHAT-BUG-2496584: High severity GIMP vulnerability
A source-level audit of GIMP's file format plugins identified 2 vulnerabilities in default-install plugins (file-psd, file-paa). Both are triggerable by opening a crafted image file — no user interaction beyond "File > Open" is required. Each finding has been independently reproduced with a standalone PoC and confirmed via AddressSanitizer or arithmetic verification in a Docker environment (Fedora 41, gcc, zlib-devel).
https://gitlab.gnome.org/GNOME/gimp/-/workitems/16509
Affected Software
Event History
Frequently Asked Questions
Are default GIMP installations affected?
Yes. The affected file-psd and file-paa plugins are installed by default, so installations with the standard plugin set are exposed.
What must happen for exploitation to occur?
An attacker needs to provide a crafted image file that is processed by an affected plugin. Opening the file through File > Open is sufficient to trigger the issue; no additional interaction is required.