
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14424 is a use-after-free vulnerability in GIMP's XCF file parsing engine that allows remote attackers to execute arbitrary code on affected installations. The flaw was reported to the vendor on November 11, 2025, and publicly disclosed on December 17, 2025, via a coordinated Zero Day Initiative advisory (ZDI-25-1138). The vulnerability affects GIMP 3.0.6 and potentially earlier versions, and requires user interaction — specifically opening a malicious XCF file. It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The vulnerability is classified as CWE-416 (Use After Free) and stems from GIMP's XCF file parser failing to validate the existence of an object before performing operations on it, resulting in a use-after-free condition (ZDI Advisory). An attacker crafts a malicious XCF file that, when opened by a victim, triggers the parser to operate on a freed memory object, potentially allowing control of program execution flow. The attack vector is local (the file must be opened by the user), requires no privileges, and has low attack complexity. The fix was committed to the GIMP repository at https://gitlab.gnome.org/GNOME/gimp/-/commit/5cc55d078b7fba995cef77d195fac325ee288ddd (ZDI Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the current GIMP process, running with the same privileges as the logged-in user. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive files accessible to the user, modify data, or crash the application. While the attack vector is local and requires user interaction, a socially engineered delivery of a malicious XCF file (e.g., via email or a malicious web page) could enable full user-level compromise (ZDI Advisory, Red Hat Bugzilla).
A proof-of-concept exploit reference is available through the Zero Day Initiative advisory (ZDI-25-1138), though full technical exploit details are not publicly released (ZDI Advisory). There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.063%, indicating a low probability of exploitation in the near term. No specific threat actor attribution has been reported.
curl, wget, or python) following the opening of an XCF file; GIMP process crashing with segmentation faults or memory corruption errors in application logs.GIMP has issued a patch addressing this vulnerability; users should update to the latest version of GIMP beyond 3.0.6 as soon as possible (ZDI Advisory). Red Hat Enterprise Linux 9 users can apply the fix via errata RHSA-2026:0914 (Red Hat Bugzilla). Debian users should apply DSA-6093-1 or equivalent distribution security updates. As a workaround, avoid opening XCF files from untrusted or unknown sources, and implement file scanning procedures before opening image files received externally.
The vulnerability was discovered by an anonymous researcher and reported through the Zero Day Initiative bug bounty program, with coordinated disclosure on December 17, 2025 (ZDI Advisory). Red Hat tracked the issue via Bugzilla and addressed it in RHEL 9 through RHSA-2026:0914 (Red Hat Bugzilla). No significant broader social media or community controversy has been noted, consistent with the moderate EPSS score and absence of active exploitation.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."