
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2048 is an out-of-bounds write vulnerability in GIMP's XWD (X Window Dump) file parser that allows remote attackers to execute arbitrary code on affected installations. The flaw was reported to the vendor on December 24, 2025, and publicly disclosed on February 19, 2026, via a coordinated Zero Day Initiative advisory. It affects GIMP 3.2.0-rc1 and was assigned a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The root cause is insufficient validation of user-supplied data during XWD file parsing, classified as CWE-787 (Out-of-bounds Write). When GIMP processes a maliciously crafted XWD file, the parser writes past the end of an allocated heap buffer, enabling memory corruption. Exploitation requires user interaction — the target must open a malicious XWD file or visit a page that triggers the file to be opened. The fix is documented in GIMP's merge request commit 57712677007793118388c5be6fb8231f22a2b341 (ZDI Advisory, GIMP MR).
Successful exploitation allows an attacker to execute arbitrary code in the context of the GIMP process running as the current user, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution could access sensitive files readable by the user, modify or delete data, and potentially use the compromised session as a foothold for further lateral movement within the system. The attack is local in scope (the file must be opened on the target machine), limiting but not eliminating the risk, particularly in environments where users routinely open image files from untrusted sources (ZDI Advisory, Red Hat Bugzilla).
A proof-of-concept exploit was published by the Zero Day Initiative on February 19, 2026 (ZDI-CAN-28591), credited to an anonymous researcher. As of the available intelligence, there is no evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.063%, reflecting a low but non-negligible probability of exploitation in the near term (ZDI Advisory).
bash, sh, curl, wget, python) shortly after opening an XWD file; GIMP process crashing or producing core dumps.GIMP has issued a patch addressing this vulnerability; the fix is available in the upstream repository via merge request commit 57712677007793118388c5be6fb8231f22a2b341. Red Hat has released errata for multiple RHEL versions: RHSA-2026:4173 (RHEL 9), RHSA-2026:5113 (RHEL 8), and additional EUS/SAP errata (RHSA-2026:5388 through RHSA-2026:5437). Debian and AlmaLinux have also issued updates. As an interim workaround, users should avoid opening XWD files from untrusted sources, and administrators may consider restricting GIMP usage or implementing application allowlisting until patched versions are deployed (Red Hat Bugzilla, ZDI Advisory).
Heise Online published a news article titled "Security update: Malicious code attacks on GIMP possible" covering the vulnerability and the need for users to apply the security update (Heise). The vulnerability was also noted in a Loginsoft Medium post covering zero-day and virtualization breach trends. Community discussion was observed on Bluesky and various Linux security advisory aggregators, reflecting broad awareness across the Linux ecosystem.
Fix availability across major Linux distributions and their releases.
bookworm
gimp: 2.10.34-1+deb12u9
sid
gimp: 3.2.0~RC3-1
trixie
gimp: 3.0.4-3+deb13u7
bionic (esm-apps)
gimp
devel
gimp
focal (esm-apps)
gimp
jammy
gimp
jammy (esm-apps)
gimp
noble
gimp
noble (esm-apps)
gimp
resolute
gimp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."