
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-79902 is a denial-of-service vulnerability in the Seattle FilmWorks (SFW) plugin bundled with GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without performing integer overflow checks, resulting in unbounded stack allocation and an application crash. The vulnerability affects GIMP versions up to and including 3.1.3 (fixed in 3.1.4 and later), and is also tracked against Red Hat Enterprise Linux 6, 7, 8, and 9. It was published on August 26, 2026, with a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, GitHub Advisory).
The root cause is classified as CWE-190 (Integer Overflow or Wraparound). The Seattle FilmWorks plugin in GIMP fails to validate integer values before using them to size a VLA on the stack, allowing a crafted SFW file to trigger an unbounded stack allocation. Exploitation requires local access and user interaction — specifically, a victim must open a malicious SFW image file in GIMP. The vulnerability was reported by Zhixi "Jace" Sun and is tracked internally by Red Hat as Bugzilla #2523512 (Red Hat Advisory, Red Hat Bugzilla, GNOME GitLab).
Successful exploitation causes GIMP to crash, resulting in a denial of service for the affected user. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability of the GIMP application. Because the attack vector is local and requires user interaction, the blast radius is confined to individual workstations where a user opens a malicious SFW file; lateral movement or data exfiltration are not applicable in this context (Red Hat Advisory, GitHub Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Red Hat Advisory). The EPSS score is approximately 0.13–0.20%, indicating a low probability of exploitation within the next 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement for user interaction (opening a crafted file), reducing the likelihood of opportunistic attacks.
.sfw files in user download directories, email attachments, or shared folders./var/log/syslog, journalctl) referencing the GIMP process terminating abnormally after opening an SFW file.GIMP versions 3.1.4 and later contain the fix; users should upgrade to at least version 3.1.4 (GNOME GitLab). Red Hat has assessed RHEL 6, 7, 8, and 9 as unaffected for their shipped packages, so no RHEL patch is expected (Red Hat Advisory). As an interim workaround, users should avoid opening SFW image files from untrusted sources, and administrators can restrict or disable the Seattle FilmWorks plugin in GIMP deployments where SFW support is not required.
Red Hat rated this vulnerability as Moderate severity, noting that an attacker must convince a user to open a crafted SFW file, which reduces the likelihood of exploitation (Red Hat Advisory). The vulnerability was reported by Zhixi "Jace" Sun and acknowledged by Red Hat Product Security. No significant broader media coverage or notable researcher commentary beyond the standard advisory disclosures has been identified.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
gimp
devel
gimp
focal (esm-apps)
gimp
jammy
gimp
jammy (esm-apps)
gimp
noble
gimp
noble (esm-apps)
gimp
resolute
gimp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."