CVE-2026-97185: 
Linux Red Hat 脆弱性の分析と軽減

概要

CVE-2026-97185 is an out-of-bounds write vulnerability in GIMP's GIMPressionist plug-in that can lead to memory corruption, application crashes, or arbitrary code execution. The flaw occurs when processing a specially crafted GIMPressionist preset file, where the plug-in fails to validate vector indices before writing into fixed-size arrays. It was disclosed on September 24, 2026, and affects GIMP 3.2.6 (a bounds check was added on the main branch). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Red Hat CVE, GitHub Advisory).

技術的な詳細

The root cause is an out-of-bounds write (CWE-787) in GIMP's GIMPressionist plug-in, specifically in presets.c. The functions set_orient_vector() and set_size_vector() parse an attacker-controlled index using atoi() and use it to write into pcvals.orient_vectors[] and pcvals.size_vectors[] — fixed-size arrays of 50 entries each (bounded by MAXORIENTVECT and MAXSIZEVECT) — without validating that the index falls within bounds. A crafted preset file containing an out-of-range or negative index triggers writes past the array boundaries, corrupting adjacent memory. Exploitation requires local access and user interaction (convincing the victim to open a malicious preset file). This flaw is distinct from CVE-2026-90947, which addressed a similar missing bounds check in the Lighting Effects plug-in (Red Hat Bugzilla, Red Hat CVE).

影響

Successful exploitation can result in high impacts to confidentiality, integrity, and availability within the context of the user running GIMP. Memory corruption caused by the out-of-bounds write may allow an attacker to execute arbitrary code, potentially gaining full control of the user's session, or cause the application to crash (denial of service). Because the attack is local and scoped to the user's context, lateral movement potential is limited, but sensitive files accessible to the user could be exposed or tampered with (Red Hat CVE, GitHub Advisory).

エクスプロイト可能性

As of the disclosure date (September 24, 2026), there are no known public proof-of-concept exploits, no reported in-the-wild exploitation, and no threat actor attribution. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires user interaction, reducing the likelihood of widespread exploitation (Red Hat CVE, GitHub Advisory).

エクスプロイテーションのステップ

  1. Craft a malicious preset file: Create a GIMPressionist preset file (.gimpressionist) with an out-of-range or negative integer value for the orient_vector or size_vector index field, exploiting the lack of bounds checking in set_orient_vector() or set_size_vector() in presets.c.
  2. Social engineering: Deliver the malicious preset file to the target user via email, file sharing, or a compromised website, convincing them it is a legitimate GIMP preset.
  3. Trigger loading: Instruct or wait for the user to open GIMP and load the crafted preset file through the GIMPressionist plug-in interface (Filters > Render > GIMPressionist > Load Preset).
  4. Memory corruption: The plug-in parses the attacker-controlled index with atoi() and writes past the bounds of pcvals.orient_vectors[] or pcvals.size_vectors[], corrupting adjacent memory.
  5. Achieve objective: Depending on memory layout and exploit refinement, the attacker may achieve a crash (denial of service) or, with further exploitation of the corrupted memory state, arbitrary code execution in the context of the user running GIMP (Red Hat Bugzilla, Red Hat CVE).

妥協の兆候

  • File System: Unexpected or unfamiliar .gimpressionist preset files in GIMP's preset directories (e.g., ~/.config/GIMP/ or ~/.gimp-*/gimpressionist/Presets/) received from external sources.
  • Process: GIMP process (gimp, gimp-2.10, or gimp-3.x) crashing unexpectedly or spawning unusual child processes after loading a preset file.
  • Logs: Application crash logs or core dumps associated with the GIMP process, particularly referencing memory access violations or segmentation faults in presets.c or the GIMPressionist plug-in.
  • Network: Outbound network connections initiated by the GIMP process to unexpected external hosts following preset file loading (may indicate post-exploitation activity if code execution is achieved).

軽減策と回避策

A bounds check fix has been committed to the GIMP main branch (GIMP 3.2.6 is confirmed affected; users should monitor upstream GIMP and distribution-specific updates for a patched release). Red Hat's official interim mitigation is to avoid loading GIMPressionist preset files from untrusted sources. Users and administrators should apply distribution patches as they become available and restrict the use of third-party GIMP preset files until a fixed version is deployed (Red Hat CVE, Red Hat Bugzilla).

コミュニティの反応

Red Hat acknowledged the vulnerability and credited Harsh Verma for reporting it. The issue was noted to be distinct from a similar prior flaw (CVE-2026-90947) in GIMP's Lighting Effects plug-in, suggesting a pattern of missing bounds checks in GIMP plug-ins. A brief mention appeared on Mastodon via @thehackerwire, but broader community or media coverage was limited at the time of disclosure (Red Hat CVE).

関連情報

Linuxディストリビューションの修正状況

主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。

Debian

影響

bookworm

gimp

影響

sid

gimp

影響

trixie

gimp

影響

Ubuntu

不明

bionic (esm-apps)

gimp

不明

devel

gimp

不明

focal (esm-apps)

gimp

不明

jammy

gimp

不明

jammy (esm-apps)

gimp

不明

noble

gimp

不明

noble (esm-apps)

gimp

不明

resolute

gimp

不明

RHEL / CentOS

影響

RHEL 8

gimp:2.8/gimp.src

影響

RHEL 9

gimp.src

影響

RHEL 10

gimp.src

影響

ソース: このレポートは AI を使用して生成されました

関連 Linux Red Hat 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-97185HIGH7.8
  • Linux Red Hat logoLinux Red Hat
  • gimp:2.8::pygobject2-doc
いいえいいえSep 24, 2026
CVE-2026-96889HIGH7.8
  • Linux Debian logoLinux Debian
  • librsvg2-tools
いいえいいえSep 23, 2026
CVE-2026-96541HIGH7.5
  • Linux Debian logoLinux Debian
  • gnome-remote-desktop
いいえいいえSep 23, 2026
CVE-2026-96545MEDIUM4.4
  • Linux Debian logoLinux Debian
  • gimp:2.8::python2-cairo-devel
いいえいいえSep 23, 2026
CVE-2026-96546LOW2.5
  • Linux Debian logoLinux Debian
  • gimp-help-browser
いいえいいえSep 23, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者