
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-82343 is a memory safety vulnerability in the file-psd plugin of GIMP (GNU Image Manipulation Program) that allows a heap out-of-bounds read and stack out-of-bounds access when processing a specially crafted PSD image file. The flaw stems from improper validation of the channel-count parameter, leading to incorrect memory bounds checking. It affects GIMP versions up to and including 3.3.1, as well as Red Hat Enterprise Linux 6.0, 7.0, 8.0, and 9.0. Disclosed on August 28, 2026, it carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, GitHub Advisory).
The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input / Classic Buffer Overflow). When GIMP's file-psd plugin parses a PSD image, it reads the channel-count field from the file header without adequately validating its value before using it to calculate memory offsets or buffer sizes. This leads to both a heap out-of-bounds read and a stack out-of-bounds access during image loading. Exploitation requires user interaction — specifically, a victim must open a maliciously crafted PSD file in GIMP — making the attack vector local with no privileges required (Red Hat Advisory, Red Hat Bugzilla). The vulnerability was reported by researcher Zhixi "Jace" Sun (Red Hat Advisory).
Successful exploitation can cause GIMP to crash, resulting in a denial of service for the affected user. Additionally, the heap out-of-bounds read may expose limited contents of process memory, constituting a low-severity information disclosure. Integrity is not impacted, and the scope is confined to the affected GIMP process without privilege escalation or lateral movement potential (Red Hat Advisory, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.117–0.183%, placing it in a low percentile for near-term exploitation likelihood. Exploitation is further constrained by the requirement for user interaction (opening a malicious PSD file), which Red Hat notes reduces the likelihood of exploitation and justifies a moderate severity rating (Red Hat Advisory).
.psd files in user download directories, email attachments, or shared folders, particularly those with anomalous file sizes or metadata./var/crash/ or ~/.local/share/) generated shortly after opening a PSD file; system logs showing GIMP process termination with a segmentation fault or similar signal.gimp-2.x or gimp-3.x) with a signal such as SIGSEGV or SIGABRT, observable via system monitoring tools or crash reporters.A patch is available in GIMP 3.2.6, released on September 10, 2026, which addresses this and other CVEs (GIMP Release). Users should upgrade to GIMP 3.2.6 or later as the primary remediation. As a temporary workaround, Red Hat advises users not to open PSD files from untrusted sources with GIMP until a patched package is available for their distribution (Red Hat Advisory). Red Hat Enterprise Linux users should monitor for updated GIMP packages via their subscription channels.
Red Hat, as the CVE Naming Authority (CNA) for this vulnerability, rated it as moderate severity and acknowledged the report from researcher Zhixi "Jace" Sun (Red Hat Advisory). The GIMP project addressed this vulnerability as part of the GIMP 3.2.6 release, which fixed 28 CVEs (GIMP Release). Coverage was noted in Linux-focused outlets highlighting the bundled security fixes in the 3.2.6 release.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
gimp
devel
gimp
focal (esm-apps)
gimp
jammy
gimp
jammy (esm-apps)
gimp
noble
gimp
noble (esm-apps)
gimp
resolute
gimp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."