CVE-2026-59091
Linux Debian 脆弱性の分析と軽減

概要

CVE-2026-59091 is a high-severity out-of-bounds write vulnerability affecting GIMP's file format plugins, specifically the file-psd and file-paa plugins. A remote attacker can exploit this flaw by tricking a user into opening a specially crafted PSD or PAA image file, potentially leading to unexpected application behavior, information disclosure, or arbitrary code execution. The vulnerability was reported on July 2, 2026, and publicly disclosed on August 10, 2026. It carries a CVSS v3.1 base score of 7.3 (High), assigned by Red Hat as the CNA (Red Hat Advisory, Github Advisory).

技術的な詳細

The root cause is classified as CWE-787 (Out-of-bounds Write), where GIMP's file format parsing code writes data beyond the bounds of an allocated buffer when processing malformed PSD or PAA image files. According to the Red Hat Bugzilla report, a source-level audit identified two vulnerabilities in default-install plugins (file-psd, file-paa), both independently reproduced with standalone proof-of-concept code and confirmed via AddressSanitizer in a Fedora 41 Docker environment. Exploitation requires only that the victim perform a standard "File > Open" action — no additional user interaction beyond opening the file is needed. The attack vector is local (the file must be opened on the victim's system), requires low privileges, and low attack complexity (Red Hat Bugzilla, Red Hat Advisory).

影響

Successful exploitation can result in high confidentiality, integrity, and availability impact on the affected system. An attacker who tricks a user into opening a malicious PSD or PAA file in GIMP could achieve arbitrary code execution with the privileges of the user running GIMP, access sensitive files readable by that user, or crash the application. Red Hat classifies this as an "Important" vulnerability capable of enabling information disclosure or potential arbitrary code execution (Red Hat Advisory).

エクスプロイト可能性

As of the disclosure date (August 10, 2026), there is no evidence of public proof-of-concept exploit code being released or active in-the-wild exploitation. However, the Red Hat Bugzilla entry notes that standalone PoC files were developed internally and used to confirm the vulnerabilities during the audit. The EPSS score is 0.0, indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Red Hat Bugzilla, Github Advisory).

エクスプロイテーションのステップ

  1. Craft a malicious image file: Create a specially crafted PSD or PAA image file that triggers the out-of-bounds write condition in GIMP's file-psd or file-paa plugin by embedding malformed data in the file structure.
  2. Deliver the file to the target: Distribute the crafted image via email attachment, file sharing platform, web download, or social engineering to a user who has GIMP installed.
  3. Induce the victim to open the file: Trick the user into opening the file in GIMP (e.g., by disguising it as a legitimate design asset or screenshot), which requires only a standard "File > Open" action.
  4. Trigger the vulnerability: Upon parsing the malformed file, GIMP's plugin writes data out of bounds, potentially corrupting memory in a way that leads to application crash, information disclosure, or arbitrary code execution with the victim user's privileges (Red Hat Bugzilla, Red Hat Advisory).

妥協の兆候

  • File System: Presence of unexpected or suspicious .psd or .paa files in user download directories, temporary folders, or email attachment staging areas.
  • Process: GIMP process (gimp, gimp-2.x) crashing unexpectedly or spawning unusual child processes (e.g., shell interpreters, network utilities) after opening an image file.
  • Logs: Application crash logs or core dumps associated with the GIMP process, particularly referencing file-psd or file-paa plugin modules; AddressSanitizer-style memory error output if GIMP is compiled with sanitizers.
  • Network: Unexpected outbound network connections originating from the GIMP process following the opening of an image file, which may indicate post-exploitation activity.

軽減策と回避策

A patch has been made available; users should update GIMP to the patched version as soon as it is distributed by their vendor or the GIMP project. Red Hat advises users to avoid opening untrusted image files, particularly those in PSD or PAA formats, with GIMP, and to exercise caution with files from unknown or suspicious sources. As an additional control, organizations can implement application allowlisting or file type restrictions to limit which image formats users can open in GIMP. The GNOME/GIMP project issue tracking the fix is available at the upstream work item (Red Hat Advisory, Github Advisory).

関連情報


ソースこのレポートは AI を使用して生成されました

関連 Linux Debian 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-71969NONE該当なし
  • Linux Debian logoLinux Debian
  • optee-os
いいえいいえAug 10, 2026
CVE-2026-71968NONE該当なし
  • Linux Debian logoLinux Debian
  • optee-os
いいえいいえAug 10, 2026
CVE-2026-71967NONE該当なし
  • Linux Debian logoLinux Debian
  • optee-os
いいえいいえAug 10, 2026
CVE-2026-6791NONE該当なし
  • Wolfi logoWolfi
  • glibc
いいえはいAug 10, 2026
CVE-2026-6368NONE該当なし
  • Linux Debian logoLinux Debian
  • glibc
いいえいいえAug 10, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者