REDHAT-BUG-2533005: High severity GIMP vulnerability

Published Sep 14, 2026
·
Updated

A flaw was found in GIMP's Lighting Effects filter. When loading a lighting preset file, lighting-ui.c reads the number of light sources from the file using fscanf() without validating the return value or bounding the parsed count against the fixed-size array of light sources (NUMLIGHTS, 6 entries). A preset file specifying more than 6 light sources causes writes past the end of the lightsource array, corrupting memory. This issue could be triggered by convincing a user to open a specially crafted lighting preset file in GIMP, potentially leading to a crash or arbitrary code execution in the context of the user running GIMP.

Affected Software

1 affected component
GIMP

Event History

Sep 14, 2026
Data Sourced
via Red Hat·11:53 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who is realistically exposed to this issue?

GIMP users who load lighting preset files are exposed. The flaw is triggered through a specially crafted preset file rather than by ordinary use alone.

2

What must an attacker do to exploit it?

An attacker must convince a user to open a crafted Lighting Effects preset file in GIMP. Successful exploitation may crash GIMP or allow code execution with the privileges of the user running it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203