
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4150 is an integer overflow vulnerability in GIMP's PSD file parser that allows remote attackers to execute arbitrary code on affected installations. The flaw was reported to the vendor on March 5, 2026, and publicly disclosed on March 19, 2026, via a coordinated Zero Day Initiative advisory (ZDI-26-217). It affects GIMP version 3.0.8 and was assigned a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, GitHub Advisory). The CVE was formally published to the NVD on April 11, 2026 (GitHub Advisory).
The root cause is an integer overflow (CWE-190) in GIMP's PSD file parsing logic, where user-supplied data is not properly validated before being used to calculate a buffer allocation size. The overflow causes an undersized buffer to be allocated, which can then be overflowed with attacker-controlled data, enabling arbitrary code execution in the context of the GIMP process. The attack vector is local (the file must be opened by the user), requires no privileges, but does require user interaction — the target must open a malicious PSD file or visit a malicious page that triggers the file to be processed. The fix is documented in a GNOME GitLab commit (GNOME Commit, ZDI Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the GIMP process, resulting in high confidentiality, integrity, and availability impact. An attacker could read, modify, or delete any files accessible to the user running GIMP, and potentially use the compromised process as a foothold for further lateral movement within the system. The scope is limited to the affected process and its user context, but on systems where GIMP is run with elevated privileges or in automated pipelines, the impact could be broader (ZDI Advisory, GitHub Advisory).
No confirmed public exploit code or proof-of-concept has been identified; the ZDI advisory describes the vulnerability but contains no exploit artifacts or reproduction steps (ZDI Advisory). There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.063%, placing it in the 13th percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the latest available data. The vulnerability was discovered by an anonymous researcher and reported through ZDI's coordinated disclosure program (ZDI Advisory).
bash, sh, cmd.exe, powershell, curl, wget, python) that are not typical for normal GIMP operation; GIMP process crashing or producing core dumps, which may indicate failed exploitation attempts.GIMP has released a patch addressing this vulnerability; users should upgrade to a version containing the fix referenced in the GNOME GitLab commit (GNOME Commit). Red Hat has issued multiple errata addressing this CVE for RHEL 8 and 9: RHSA-2026:16484, RHSA-2026:17533, RHSA-2026:19362, RHSA-2026:20552, RHSA-2026:20553, RHSA-2026:20554, and RHSA-2026:20691 (Red Hat Bugzilla). openSUSE and Debian have also issued security updates for their GIMP packages. As a workaround until patching is possible, users should avoid opening PSD files from untrusted sources and disable PSD file handling in GIMP if not required for their workflow.
The vulnerability was disclosed through Trend Micro's Zero Day Initiative program and credited to an anonymous researcher, with coordinated public release on March 19, 2026 (ZDI Advisory). Multiple Linux distributions including Red Hat, openSUSE, Debian, Amazon Linux, and AlmaLinux issued security advisories and patched packages in the weeks following disclosure, indicating broad vendor response. Coverage appeared on Linux security news aggregators and community sites, reflecting routine but attentive community response to a high-severity image parsing vulnerability in a widely used open-source application.
Fix availability across major Linux distributions and their releases.
bookworm
gimp: 2.10.34-1+deb12u10
sid
gimp: 3.2.0-1
trixie
gimp: 3.0.4-3+deb13u8
bionic (esm-apps)
gimp
devel
gimp
focal (esm-apps)
gimp
jammy
gimp
jammy (esm-apps)
gimp
noble
gimp
noble (esm-apps)
gimp
resolute
gimp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."