<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>GIMP (All Versions Prior to Fix) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/gimp-all-versions-prior-to-fix/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 17:34:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/gimp-all-versions-prior-to-fix/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Out-of-Bounds Write Vulnerability in GIMP Lighting Effects Filter (CVE-2026-90947)</title><link>https://feed.craftedsignal.io/briefs/2026-09-gimp-oob-write/</link><pubDate>Mon, 14 Sep 2026 17:34:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-gimp-oob-write/</guid><description>GIMP contains an out-of-bounds write vulnerability in its Lighting Effects filter, allowing potential arbitrary code execution when processing a maliciously crafted lighting preset file.</description><content:encoded><![CDATA[<p>A memory corruption vulnerability (CVE-2026-90947) has been identified in the GIMP image manipulation software. The flaw resides within the Lighting Effects filter, which fails to correctly validate the number of light sources defined within a GIMP lighting preset file. When a user opens a specially crafted preset file containing an unexpected number of light sources, the application performs an out-of-bounds write operation, leading to memory corruption. This vulnerability exposes users to potential application crashes or, in specific scenarios, arbitrary code execution in the context of the user running the application. This issue impacts GIMP across all supported platforms, including Windows, Linux, and macOS. Defenders should prioritize patching GIMP versions to the latest available release as identified by the project's security advisories.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-90947 could lead to full compromise of the user account running GIMP. This threat is particularly relevant in environments where users frequently import or share graphical design presets. If the application is running with elevated privileges, the impact of arbitrary code execution is significantly magnified. There is currently no report of large-scale exploitation in the wild, but the nature of the flaw makes it a viable candidate for targeted social engineering attacks.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all instances of GIMP to the latest version provided by the GIMP development team that addresses CVE-2026-90947.</li>
<li>Implement application allowlisting or restricted execution policies for image processing software to limit the impact of potential arbitrary code execution.</li>
<li>Educate users regarding the risks of opening external preset files or image configuration files from untrusted sources.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>