ZDI-CAN-27830: ZDI-25-972: Krita TGA File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Oct 27, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Krita. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-59820.
Affected Software
1 affected component
KDE Krita
Event History
Oct 27, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-27830?
The severity of ZDI-CAN-27830 is rated at 7.8 on the CVSS scale.
2
How do I fix ZDI-CAN-27830?
To fix ZDI-CAN-27830, update Krita to the latest version provided by the vendor.
3
What type of attack can ZDI-CAN-27830 enable?
ZDI-CAN-27830 can enable remote attackers to execute arbitrary code on affected installations of Krita.
4
Is user interaction required to exploit ZDI-CAN-27830?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file.
5
Which software is affected by ZDI-CAN-27830?
The affected software for ZDI-CAN-27830 is KDE Krita.