A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of memory contents.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
To mitigate this vulnerability, do not open PSD files from untrusted sources with GIMP.
References
History
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of memory contents. | |
| Title | Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-120 | |
| CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-28T16:26:13.284Z
Reserved: 2026-08-28T16:11:58.606Z
Link: CVE-2026-82343
No data.
Status : Awaiting Analysis
Published: 2026-08-28T20:20:21.527
Modified: 2026-08-28T21:17:10.720
Link: CVE-2026-82343
No data.
OpenCVE Enrichment
No data.
Weaknesses