
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40918 is a denial-of-service vulnerability in GIMP's PVR image loader caused by a stack-based buffer overflow and out-of-bounds read when processing specially crafted PVR image files with large dimensions. It was disclosed on April 15, 2026, and affects GIMP across Red Hat Enterprise Linux versions 6.0, 7.0, 8.0, and 9.0. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, GitHub Advisory).
The root cause is an incorrect calculation of buffer size (CWE-131) in GIMP's PVR image loader, which also results in an out-of-bounds read (CWE-125). When GIMP processes a PVR image file with abnormally large dimensions, the loader fails to correctly compute the required buffer size, leading to a stack-based buffer overflow that crashes the application. Exploitation requires local access and user interaction — specifically, a user must open a maliciously crafted PVR file. The flaw was reported via Red Hat's OSIDB system and tracked in Red Hat Bugzilla (Red Hat Bugzilla, GitHub Advisory).
Successful exploitation results in a crash of the GIMP application, causing a denial of service with high availability impact. There is no impact to confidentiality or data integrity, and the scope is limited to the affected application instance. Systems that routinely process untrusted PVR image files — such as those used in automated image processing pipelines — are at elevated risk (Red Hat CVE, Red Hat Bugzilla).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-40918. The EPSS score is approximately 0.013–0.017%, placing it in the 4th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (GitHub Advisory).
Users should update GIMP to a patched version once available from their distribution or upstream vendor. Red Hat has acknowledged the vulnerability and it is tracked as a security response bug; users on Red Hat Enterprise Linux should monitor Red Hat advisories for updated GIMP packages. As an interim workaround, avoid opening PVR image files from untrusted sources in GIMP, and restrict automated image processing pipelines from handling untrusted PVR files (Red Hat CVE, Red Hat Bugzilla).
Coverage of CVE-2026-40918 has been limited, with the vulnerability noted in automated security feeds and vulnerability databases shortly after disclosure. Heise Online published a related article on GIMP vulnerabilities around the same timeframe, though it focused on a separate GIF-related code injection issue rather than this specific CVE. No notable researcher commentary or significant community discussion specific to this vulnerability has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."