
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0797 is a heap-based buffer overflow vulnerability in GIMP's ICO file parser, enabling remote attackers to execute arbitrary code on affected systems. The vulnerability was reported to the vendor on December 24, 2025, and publicly disclosed by the Zero Day Initiative on January 30, 2026. The confirmed affected version is GIMP 3.2.0-rc1, with patches subsequently issued by GIMP and downstream Linux distributions. It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The root cause is insufficient validation of user-supplied data length before copying it into a heap-based buffer during ICO file parsing, classified as CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write). An attacker exploits this by crafting a malicious ICO file with an oversized data field that overflows the heap buffer when processed by GIMP's ICO parser. Exploitation requires user interaction — the target must open a malicious ICO file or visit a web page that triggers GIMP's file parsing (e.g., via a browser plugin or file association). The fix is documented in GNOME GitLab commit 69cc6b1a6645dc9c4d7b484483dbe6a84b922b9c (ZDI Advisory, GNOME GitLab).
Successful exploitation allows an attacker to execute arbitrary code in the context of the GIMP process running as the current user, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive files accessible to the user, modify or delete data, or crash the application. While the attack vector is local (requiring the user to open a file), the threat is realistic via social engineering or malicious web content that delivers a crafted ICO file (ZDI Advisory, Red Hat Bugzilla).
A proof-of-concept exploit was published by the Zero Day Initiative on January 30, 2026, as part of their coordinated disclosure (ZDI Advisory). As of the time of reporting, there is no evidence of active in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.058% (low probability of near-term exploitation). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
bash, sh, curl, wget, python) shortly after opening an ICO file; GIMP process crashing with segmentation faults or heap corruption errors.GIMP has issued a patch addressing this vulnerability, with the fix available in the GNOME GitLab repository (commit 69cc6b1a6645dc9c4d7b484483dbe6a84b922b9c). Red Hat has released multiple errata addressing this issue across RHEL 8 and RHEL 9 variants, including RHSA-2026:4173 (RHEL 9), RHSA-2026:5113 (RHEL 8), and several Extended Update Support and SAP Solutions advisories (RHSA-2026:5388 through RHSA-2026:5437). Debian and AlmaLinux/Rocky Linux have also issued updates. As an interim workaround, users should avoid opening ICO files from untrusted sources and exercise caution when visiting unfamiliar web pages that may trigger GIMP file parsing (Red Hat Bugzilla, ZDI Advisory).
The vulnerability was credited to an anonymous researcher through the Zero Day Initiative's bug bounty program and disclosed on January 30, 2026. Social media activity was observed on Mastodon and Bluesky via security news accounts such as @thehackerwire, indicating moderate community awareness. Linux security outlets including LinuxSecurity.com and Pro-Linux.de covered the downstream distribution patches. No major vendor statements beyond the patch releases have been identified.
Fix availability across major Linux distributions and their releases.
bookworm
gimp: 2.10.34-1+deb12u9
sid
gimp: 3.2.0~RC3-1
trixie
gimp: 3.0.4-3+deb13u7
bionic (esm-apps)
gimp
devel
gimp
focal (esm-apps)
gimp
jammy
gimp
jammy (esm-apps)
gimp
noble
gimp
noble (esm-apps)
gimp
resolute
gimp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."