CVE-2026-40918
Alma Linux vulnerability analysis and mitigation

Overview

CVE-2026-40918 is a denial-of-service vulnerability in GIMP's PVR image loader caused by a stack-based buffer overflow and out-of-bounds read when processing specially crafted PVR image files with large dimensions. It was disclosed on April 15, 2026, and affects GIMP across Red Hat Enterprise Linux versions 6.0, 7.0, 8.0, and 9.0. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, GitHub Advisory).

Technical details

The root cause is an incorrect calculation of buffer size (CWE-131) in GIMP's PVR image loader, which also results in an out-of-bounds read (CWE-125). When GIMP processes a PVR image file with abnormally large dimensions, the loader fails to correctly compute the required buffer size, leading to a stack-based buffer overflow that crashes the application. Exploitation requires local access and user interaction — specifically, a user must open a maliciously crafted PVR file. The flaw was reported via Red Hat's OSIDB system and tracked in Red Hat Bugzilla (Red Hat Bugzilla, GitHub Advisory).

Impact

Successful exploitation results in a crash of the GIMP application, causing a denial of service with high availability impact. There is no impact to confidentiality or data integrity, and the scope is limited to the affected application instance. Systems that routinely process untrusted PVR image files — such as those used in automated image processing pipelines — are at elevated risk (Red Hat CVE, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-40918. The EPSS score is approximately 0.013–0.017%, placing it in the 4th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (GitHub Advisory).

Mitigation and workarounds

Users should update GIMP to a patched version once available from their distribution or upstream vendor. Red Hat has acknowledged the vulnerability and it is tracked as a security response bug; users on Red Hat Enterprise Linux should monitor Red Hat advisories for updated GIMP packages. As an interim workaround, avoid opening PVR image files from untrusted sources in GIMP, and restrict automated image processing pipelines from handling untrusted PVR files (Red Hat CVE, Red Hat Bugzilla).

Community reactions

Coverage of CVE-2026-40918 has been limited, with the vulnerability noted in automated security feeds and vulnerability databases shortly after disclosure. Heise Online published a related article on GIMP vulnerabilities around the same timeframe, though it focused on a separate GIF-related code injection issue rather than this specific CVE. No notable researcher commentary or significant community discussion specific to this vulnerability has been identified.

Additional resources


SourceThis report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-70906HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.7.0-openjdk-demo
NoYesAug 18, 2026
CVE-2026-61308MEDIUM6.8
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-openjdk-fastdebug
NoYesAug 18, 2026
CVE-2026-70907MEDIUM5.3
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.8.0-openjdk.src
NoYesAug 18, 2026
CVE-2026-60589LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-25-openjdk-src
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management