<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>GIMP (Affected Versions) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/gimp-affected-versions/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 15:33:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/gimp-affected-versions/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Heap-Based Buffer Overflow in GIMP PSP File Loader</title><link>https://feed.craftedsignal.io/briefs/2026-09-gimp-psp-overflow/</link><pubDate>Mon, 14 Sep 2026 15:33:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-gimp-psp-overflow/</guid><description>A heap-based buffer overflow in GIMP's PSP file loader, tracked as CVE-2026-90949, allows attackers to trigger crashes or arbitrary code execution via crafted image files.</description><content:encoded><![CDATA[<p>CVE-2026-90949 is a vulnerability identified in the Paint Shop Pro (PSP) file loader component of the GIMP image manipulation software. The issue arises during the processing of compressed selection channels within PSP files. A mismatch between the allocated buffer size and the actual amount of data decompressed by the loader results in a heap-based buffer overflow. An attacker can leverage this flaw by distributing a specially crafted PSP file to a victim. When the victim opens the malicious file using an affected version of GIMP, the resulting memory corruption may cause the application to crash or enable the execution of arbitrary code in the context of the user running the application. This vulnerability poses a significant risk to end-users who may interact with untrusted image files.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-90949 can lead to a denial-of-service (application crash) or full code execution on the host machine. This affects any user or organization utilizing GIMP for processing image assets. The impact is elevated if the application is run with higher-privilege user context.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all systems where GIMP is installed and monitor vendor release notes for the patched version addressing CVE-2026-90949.</li>
<li>Implement strict email and web gateway filtering to block PSP (Paint Shop Pro) file formats from untrusted external sources if your environment does not require this file format.</li>
<li>Advise end-users to avoid opening PSP files from unknown or unverified sources until the software is patched.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>memory-corruption</category></item></channel></rss>