
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-97185 is an out-of-bounds write vulnerability in GIMP's GIMPressionist plug-in that can lead to memory corruption, application crashes, or arbitrary code execution. The flaw occurs when processing a specially crafted GIMPressionist preset file, where the plug-in fails to validate vector indices before writing into fixed-size arrays. It was disclosed on September 24, 2026, and affects GIMP 3.2.6 (a bounds check was added on the main branch). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Red Hat CVE, GitHub Advisory).
The root cause is an out-of-bounds write (CWE-787) in GIMP's GIMPressionist plug-in, specifically in presets.c. The functions set_orient_vector() and set_size_vector() parse an attacker-controlled index using atoi() and use it to write into pcvals.orient_vectors[] and pcvals.size_vectors[] — fixed-size arrays of 50 entries each (bounded by MAXORIENTVECT and MAXSIZEVECT) — without validating that the index falls within bounds. A crafted preset file containing an out-of-range or negative index triggers writes past the array boundaries, corrupting adjacent memory. Exploitation requires local access and user interaction (convincing the victim to open a malicious preset file). This flaw is distinct from CVE-2026-90947, which addressed a similar missing bounds check in the Lighting Effects plug-in (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation can result in high impacts to confidentiality, integrity, and availability within the context of the user running GIMP. Memory corruption caused by the out-of-bounds write may allow an attacker to execute arbitrary code, potentially gaining full control of the user's session, or cause the application to crash (denial of service). Because the attack is local and scoped to the user's context, lateral movement potential is limited, but sensitive files accessible to the user could be exposed or tampered with (Red Hat CVE, GitHub Advisory).
As of the disclosure date (September 24, 2026), there are no known public proof-of-concept exploits, no reported in-the-wild exploitation, and no threat actor attribution. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires user interaction, reducing the likelihood of widespread exploitation (Red Hat CVE, GitHub Advisory).
.gimpressionist) with an out-of-range or negative integer value for the orient_vector or size_vector index field, exploiting the lack of bounds checking in set_orient_vector() or set_size_vector() in presets.c.atoi() and writes past the bounds of pcvals.orient_vectors[] or pcvals.size_vectors[], corrupting adjacent memory..gimpressionist preset files in GIMP's preset directories (e.g., ~/.config/GIMP/ or ~/.gimp-*/gimpressionist/Presets/) received from external sources.gimp, gimp-2.10, or gimp-3.x) crashing unexpectedly or spawning unusual child processes after loading a preset file.presets.c or the GIMPressionist plug-in.A bounds check fix has been committed to the GIMP main branch (GIMP 3.2.6 is confirmed affected; users should monitor upstream GIMP and distribution-specific updates for a patched release). Red Hat's official interim mitigation is to avoid loading GIMPressionist preset files from untrusted sources. Users and administrators should apply distribution patches as they become available and restrict the use of third-party GIMP preset files until a fixed version is deployed (Red Hat CVE, Red Hat Bugzilla).
Red Hat acknowledged the vulnerability and credited Harsh Verma for reporting it. The issue was noted to be distinct from a similar prior flaw (CVE-2026-90947) in GIMP's Lighting Effects plug-in, suggesting a pattern of missing bounds checks in GIMP plug-ins. A brief mention appeared on Mastodon via @thehackerwire, but broader community or media coverage was limited at the time of disclosure (Red Hat CVE).
主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"