CVE-2026-2047
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-2047 is a heap-based buffer overflow vulnerability in GIMP's ICNS file parser that allows remote attackers to execute arbitrary code on affected installations. The flaw was reported to the vendor on December 4, 2025, and publicly disclosed on February 19, 2026, via a coordinated Zero Day Initiative advisory. The affected product is GIMP version 3.0.6, and a patch has been issued. It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), CWE-131 (Incorrect Calculation of Buffer Size), and CWE-787 (Out-of-bounds Write). The root cause is insufficient validation of the length of user-supplied data before it is copied into a heap-based buffer during ICNS file parsing. An attacker exploits this by crafting a malicious ICNS file (or embedding it in a malicious web page) and inducing the target user to open it with GIMP, triggering the overflow and enabling code execution in the context of the GIMP process. The fix is documented in the GNOME GitLab merge request commit (ZDI Advisory, GNOME GitLab).

Impact

Successful exploitation allows an attacker to execute arbitrary code within the context of the GIMP process, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker who achieves code execution could access sensitive files, modify data, or use the compromised process as a foothold for further lateral movement within the environment. The attack vector is local (the malicious file must be opened by the user), but the file can be delivered remotely via email, web download, or a malicious page (ZDI Advisory, Red Hat Bugzilla).

Exploitability

A proof-of-concept advisory is publicly available via the Zero Day Initiative (ZDI-26-120), though no weaponized exploit kit or in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability was reported anonymously to ZDI and disclosed after coordinated vendor patching. The EPSS score is approximately 0.058%, indicating a currently low probability of active exploitation. There is no indication this CVE has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (ZDI Advisory).

Exploitation steps

  1. Craft a malicious ICNS file: Create a specially crafted Apple Icon Image (ICNS) file with a manipulated data length field that exceeds the allocated heap buffer size when parsed by GIMP's ICNS parser.
  2. Deliver the payload: Distribute the malicious ICNS file to the target via email attachment, a malicious web page with a downloadable file, or a shared file system.
  3. Induce user interaction: Social-engineer the target user into opening the malicious ICNS file with GIMP (e.g., by disguising it as a legitimate icon or image file).
  4. Trigger the overflow: When GIMP parses the ICNS file, the lack of length validation causes user-supplied data to overflow the heap buffer, corrupting adjacent heap memory.
  5. Achieve code execution: By controlling the overflow data, the attacker overwrites heap metadata or function pointers to redirect execution flow, achieving arbitrary code execution in the context of the GIMP process (ZDI Advisory, Red Hat Bugzilla).

Indicators of compromise

  • File System: Unexpected ICNS files in user download directories, temporary folders, or email attachment staging areas; new or modified files in the GIMP configuration directory following an unexpected GIMP session.
  • Process: Unusual child processes spawned by the GIMP process (e.g., bash, sh, curl, wget, python) that are not typical for image editing workflows; GIMP process crashing or producing core dumps unexpectedly.
  • Logs: Application crash logs or core dumps referencing GIMP's ICNS parsing code; system logs showing unexpected network connections originating from the GIMP process.
  • Network: Outbound connections from the GIMP process to external IP addresses or domains, particularly shortly after opening an ICNS file.

Mitigation and workarounds

GIMP has issued a patch addressing this vulnerability; users should update to the fixed version as soon as possible. The fix is available via the GNOME GitLab merge request and has been addressed in Red Hat Enterprise Linux 9 through RHSA-2026:4173 (released March 10, 2026), as well as Debian and other Linux distributions. As an interim workaround, users should avoid opening ICNS files from untrusted or unknown sources, and administrators should consider restricting GIMP execution in high-security environments (ZDI Advisory, Red Hat Errata, Red Hat Bugzilla).

Community reactions

Heise Online published a news article titled "Security update: Malicious code attacks on GIMP possible" covering the vulnerability and the availability of security updates. Social media posts on Mastodon and Bluesky from accounts such as @thehackerwire and @cyberhub.blog highlighted the advisory shortly after public disclosure. The vulnerability received coverage across Linux security news outlets including LinuxSecurity.com and LinuxCompatible.org, particularly in the context of Debian and AlmaLinux/Rocky Linux package updates (Heise Online).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

gimp

Fixed

sid

gimp: 3.2.0~RC3-1

Fixed

trixie

gimp: 3.0.4-3+deb13u7

Fixed

Ubuntu

Unknown

bionic (esm-apps)

gimp

Unknown

devel

gimp

Unknown

focal (esm-apps)

gimp

Unknown

jammy

gimp

Unknown

jammy (esm-apps)

gimp

Unknown

noble

gimp

Unknown

noble (esm-apps)

gimp

Unknown

resolute

gimp

Unknown

RHEL / CentOS

Fixed

RHEL 8

Not Affected

RHEL 9

:appstream:gimp-2:3.0.4-1.el9_7.4.src

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management