Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-82343
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-82343 is a memory safety vulnerability in the file-psd plugin of GIMP (GNU Image Manipulation Program) that allows a heap out-of-bounds read and stack out-of-bounds access when processing a specially crafted PSD image file. The flaw stems from improper validation of the channel-count parameter, leading to incorrect memory bounds checking. It affects GIMP versions up to and including 3.3.1, as well as Red Hat Enterprise Linux 6.0, 7.0, 8.0, and 9.0. Disclosed on August 28, 2026, it carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input / Classic Buffer Overflow). When GIMP's file-psd plugin parses a PSD image, it reads the channel-count field from the file header without adequately validating its value before using it to calculate memory offsets or buffer sizes. This leads to both a heap out-of-bounds read and a stack out-of-bounds access during image loading. Exploitation requires user interaction — specifically, a victim must open a maliciously crafted PSD file in GIMP — making the attack vector local with no privileges required (Red Hat Advisory, Red Hat Bugzilla). The vulnerability was reported by researcher Zhixi "Jace" Sun (Red Hat Advisory).

Impact

Successful exploitation can cause GIMP to crash, resulting in a denial of service for the affected user. Additionally, the heap out-of-bounds read may expose limited contents of process memory, constituting a low-severity information disclosure. Integrity is not impacted, and the scope is confined to the affected GIMP process without privilege escalation or lateral movement potential (Red Hat Advisory, GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.117–0.183%, placing it in a low percentile for near-term exploitation likelihood. Exploitation is further constrained by the requirement for user interaction (opening a malicious PSD file), which Red Hat notes reduces the likelihood of exploitation and justifies a moderate severity rating (Red Hat Advisory).

Exploitation steps

  1. Craft a malicious PSD file: Create a specially crafted Adobe Photoshop PSD image file with an invalid or excessively large channel-count value in the file header, designed to trigger improper memory bounds checking in GIMP's file-psd plugin.
  2. Deliver the file to the target: Use social engineering, phishing, or file-sharing platforms to convince a GIMP user to open the malicious PSD file. The attack is local and requires user interaction.
  3. Trigger the vulnerability: When the victim opens the crafted PSD file in GIMP, the file-psd plugin reads the malformed channel-count parameter without proper validation, causing a heap out-of-bounds read and/or stack out-of-bounds access.
  4. Achieve denial of service or memory disclosure: The out-of-bounds memory access causes GIMP to crash (denial of service), or in some cases may allow limited disclosure of heap or stack memory contents from the GIMP process (Red Hat Advisory, Red Hat Bugzilla).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .psd files in user download directories, email attachments, or shared folders, particularly those with anomalous file sizes or metadata.
  • Logs: GIMP crash reports or core dump files (e.g., in /var/crash/ or ~/.local/share/) generated shortly after opening a PSD file; system logs showing GIMP process termination with a segmentation fault or similar signal.
  • Process: Abnormal termination of the GIMP process (gimp-2.x or gimp-3.x) with a signal such as SIGSEGV or SIGABRT, observable via system monitoring tools or crash reporters.

Mitigation and workarounds

A patch is available in GIMP 3.2.6, released on September 10, 2026, which addresses this and other CVEs (GIMP Release). Users should upgrade to GIMP 3.2.6 or later as the primary remediation. As a temporary workaround, Red Hat advises users not to open PSD files from untrusted sources with GIMP until a patched package is available for their distribution (Red Hat Advisory). Red Hat Enterprise Linux users should monitor for updated GIMP packages via their subscription channels.

Community reactions

Red Hat, as the CVE Naming Authority (CNA) for this vulnerability, rated it as moderate severity and acknowledged the report from researcher Zhixi "Jace" Sun (Red Hat Advisory). The GIMP project addressed this vulnerability as part of the GIMP 3.2.6 release, which fixed 28 CVEs (GIMP Release). Coverage was noted in Linux-focused outlets highlighting the bundled security fixes in the 3.2.6 release.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

gimp

Affected

sid

gimp: 3.2.6-1

Fixed

trixie

gimp

Affected

Ubuntu

Unknown

bionic (esm-apps)

gimp

Unknown

devel

gimp

Unknown

focal (esm-apps)

gimp

Unknown

jammy

gimp

Unknown

jammy (esm-apps)

gimp

Unknown

noble

gimp

Unknown

noble (esm-apps)

gimp

Unknown

resolute

gimp

Unknown

RHEL / CentOS

Affected

RHEL 8

gimp:2.8/gimp.src

Affected

RHEL 9

gimp.src

Affected

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • gcc10-binutils
NoNoSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management