Skip to content
Threat Feed
high advisory updated

Heap-Based Buffer Overflow in GIMP PSP File Loader

A heap-based buffer overflow in GIMP's PSP file loader, tracked as CVE-2026-90949, allows attackers to trigger crashes or arbitrary code execution via crafted image files.

CVE search metadata

CVE search record: CVE-2026-90949. Severity: high. CVSS: 7.8. KEV: no. Product: GIMP (affected versions), GIMP. Brief: Heap-Based Buffer Overflow in GIMP PSP File Loader. Brief link: https://feed.craftedsignal.io/briefs/2026-09-gimp-psp-overflow/

What's new

  • 1. new product Sep 15, 13:05 via bsi

CVE-2026-90949 is a vulnerability identified in the Paint Shop Pro (PSP) file loader component of the GIMP image manipulation software. The issue arises during the processing of compressed selection channels within PSP files. A mismatch between the allocated buffer size and the actual amount of data decompressed by the loader results in a heap-based buffer overflow. An attacker can leverage this flaw by distributing a specially crafted PSP file to a victim. When the victim opens the malicious file using an affected version of GIMP, the resulting memory corruption may cause the application to crash or enable the execution of arbitrary code in the context of the user running the application. This vulnerability poses a significant risk to end-users who may interact with untrusted image files.

Impact

Successful exploitation of CVE-2026-90949 can lead to a denial-of-service (application crash) or full code execution on the host machine. This affects any user or organization utilizing GIMP for processing image assets. The impact is elevated if the application is run with higher-privilege user context.

Recommendation

  • Identify all systems where GIMP is installed and monitor vendor release notes for the patched version addressing CVE-2026-90949.
  • Implement strict email and web gateway filtering to block PSP (Paint Shop Pro) file formats from untrusted external sources if your environment does not require this file format.
  • Advise end-users to avoid opening PSP files from unknown or unverified sources until the software is patched.

Mitigations

Monitor for and apply GIMP patches as released to address CVE-2026-90949

immediate IT Operations

CVE-2026-90949