
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2047 is a heap-based buffer overflow vulnerability in GIMP's ICNS file parser that allows remote attackers to execute arbitrary code on affected installations. The flaw was reported to the vendor on December 4, 2025, and publicly disclosed on February 19, 2026, via a coordinated Zero Day Initiative advisory. The affected product is GIMP version 3.0.6, and a patch has been issued. It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), CWE-131 (Incorrect Calculation of Buffer Size), and CWE-787 (Out-of-bounds Write). The root cause is insufficient validation of the length of user-supplied data before it is copied into a heap-based buffer during ICNS file parsing. An attacker exploits this by crafting a malicious ICNS file (or embedding it in a malicious web page) and inducing the target user to open it with GIMP, triggering the overflow and enabling code execution in the context of the GIMP process. The fix is documented in the GNOME GitLab merge request commit (ZDI Advisory, GNOME GitLab).
Successful exploitation allows an attacker to execute arbitrary code within the context of the GIMP process, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker who achieves code execution could access sensitive files, modify data, or use the compromised process as a foothold for further lateral movement within the environment. The attack vector is local (the malicious file must be opened by the user), but the file can be delivered remotely via email, web download, or a malicious page (ZDI Advisory, Red Hat Bugzilla).
A proof-of-concept advisory is publicly available via the Zero Day Initiative (ZDI-26-120), though no weaponized exploit kit or in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability was reported anonymously to ZDI and disclosed after coordinated vendor patching. The EPSS score is approximately 0.058%, indicating a currently low probability of active exploitation. There is no indication this CVE has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (ZDI Advisory).
bash, sh, curl, wget, python) that are not typical for image editing workflows; GIMP process crashing or producing core dumps unexpectedly.GIMP has issued a patch addressing this vulnerability; users should update to the fixed version as soon as possible. The fix is available via the GNOME GitLab merge request and has been addressed in Red Hat Enterprise Linux 9 through RHSA-2026:4173 (released March 10, 2026), as well as Debian and other Linux distributions. As an interim workaround, users should avoid opening ICNS files from untrusted or unknown sources, and administrators should consider restricting GIMP execution in high-security environments (ZDI Advisory, Red Hat Errata, Red Hat Bugzilla).
Heise Online published a news article titled "Security update: Malicious code attacks on GIMP possible" covering the vulnerability and the availability of security updates. Social media posts on Mastodon and Bluesky from accounts such as @thehackerwire and @cyberhub.blog highlighted the advisory shortly after public disclosure. The vulnerability received coverage across Linux security news outlets including LinuxSecurity.com and LinuxCompatible.org, particularly in the context of Debian and AlmaLinux/Rocky Linux package updates (Heise Online).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
gimp
devel
gimp
focal (esm-apps)
gimp
jammy
gimp
jammy (esm-apps)
gimp
noble
gimp
noble (esm-apps)
gimp
resolute
gimp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."