
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6384 is a classic buffer overflow vulnerability in GIMP's GIF image loading component, specifically within the ReadJeffsImage function. A specially crafted GIF file can cause GIMP to write beyond an allocated buffer, potentially leading to denial of service or arbitrary code execution. The vulnerability was disclosed on April 15, 2026, and affects GIMP as packaged on Red Hat Enterprise Linux 6, 7, 8, and 9. It carries a CVSS v3.1 base score of 7.8 (High) per Feedly/Red Hat, and 7.3 (High) per the GitHub Advisory Database and ENISA (Red Hat CVE, GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input — 'Classic Buffer Overflow'). The vulnerable code resides in GIMP's GIF image loader, in the ReadJeffsImage function, which fails to validate that input data fits within the allocated output buffer before copying. An attacker exploits this by crafting a malicious GIF file and convincing a user to open it in GIMP; no elevated privileges are required, but user interaction is necessary. Successful exploitation can corrupt adjacent memory, potentially enabling control-flow hijacking for arbitrary code execution (Red Hat Bugzilla, GitHub Advisory).
Successful exploitation can result in a denial of service (application crash) or arbitrary code execution in the context of the user running GIMP, affecting confidentiality, integrity, and availability at a high level. Because the attack is local and requires user interaction (opening a malicious GIF), the blast radius is limited to the affected user's session and data accessible to that account. Lateral movement potential is low unless the compromised user account has elevated privileges or access to sensitive shared resources (Red Hat CVE, GitHub Advisory).
As of the time of disclosure, no public proof-of-concept exploit code or in-the-wild exploitation has been reported. The EPSS score is approximately 0.013% (0.000130), indicating a very low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (GitHub Advisory, Red Hat CVE).
ReadJeffsImage parsing logic, designed to overflow the allocated buffer during GIF loading.ReadJeffsImage function processes the file and writes beyond the allocated buffer boundary.gimp, gimp-2.10, etc.) crashing unexpectedly or generating core dump files after opening a GIF image.core, core.<pid>) in the working directory or /var/crash/./var/log/messages, journalctl) referencing the GIMP process; entries from abrtd or similar crash reporting daemons related to GIMP.No fixed GIMP version has been specified in the available advisories; the Red Hat Bugzilla entry shows the bug status as 'NEW' with no 'Fixed In Version' listed, indicating a patch may not yet be available for affected Red Hat Enterprise Linux packages (Red Hat Bugzilla). As a workaround, users should avoid opening GIF files from untrusted sources in GIMP. Organizations should monitor Red Hat security advisories for errata updates addressing this CVE and apply patches promptly once released (Red Hat CVE). Restricting GIMP usage to trusted file sources and enabling OS-level exploit mitigations (e.g., ASLR, SELinux) can reduce risk in the interim.
Heise (a German technology news outlet) published an English-language article titled "Gimp: Unpatched vulnerability allows code injection with GIFs," highlighting the lack of an available patch at the time of disclosure (Heise). RedPacket Security flagged the vulnerability via social media on Mastodon, and automated CVE tracking accounts on Bluesky also noted the disclosure. Community reaction has been moderate, with attention focused on the unpatched status of the vulnerability.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
gimp
devel
gimp
focal (esm-apps)
gimp
jammy
gimp
jammy (esm-apps)
gimp
noble
gimp
noble (esm-apps)
gimp
resolute
gimp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."