REDHAT-BUG-2525644: Medium severity GIMP file-psd plugin vulnerability
Published Aug 28, 2026
·Updated
A flaw was found in the file-psd plugin in GIMP, affecting all versions. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of memory contents.
Affected Software
1 affected component
GIMP file-psd plugin=all
Event History
Aug 28, 2026
Data Sourced
via Red Hat·04:12 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which GIMP deployments are affected?
The issue affects all versions of the GIMP file-psd plugin.
2
What must an attacker do to trigger the flaw?
An attacker needs to provide a specially crafted PSD image file that is processed by the file-psd plugin.