<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-97185 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-97185/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 24 Sep 2026 10:46:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-97185/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Code Execution in GIMP via GIMPressionist Preset Files</title><link>https://feed.craftedsignal.io/briefs/2026-09-gimp-memory-corruption/</link><pubDate>Thu, 24 Sep 2026 10:46:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-gimp-memory-corruption/</guid><description>A memory corruption vulnerability in GIMP allows attackers to achieve arbitrary code execution by tricking a user into opening a maliciously crafted GIMPressionist preset file.</description><content:encoded><![CDATA[<p>A memory corruption vulnerability (CVE-2026-97185) exists in the GIMPressionist plug-in within GIMP. The flaw occurs because the plug-in fails to properly validate vector indices before performing write operations into fixed-size arrays when parsing GIMPressionist preset files. An attacker can exploit this by crafting a malicious preset file that triggers an out-of-bounds write. If a user is convinced to load this specially crafted file into GIMP, the resulting memory corruption can lead to application crashes or allow for arbitrary code execution in the context of the user running the software. This vulnerability represents a significant risk for users who frequently import configuration or preset files from untrusted sources, as the exploitation is triggered through standard application functionality.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an attacker to gain code execution on the target system. This could lead to full system compromise, data theft, or the installation of persistent backdoors depending on the privileges of the user running GIMP. The attack surface includes any environment where GIMP is installed on Windows, Linux, or macOS systems.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection and mitigation should focus on preventing the execution of GIMP with untrusted configuration files and monitoring for abnormal process behavior associated with GIMP.</p>
<ul>
<li>Update GIMP to the latest version once a patch is provided by the GIMP development team to resolve CVE-2026-97185.</li>
<li>Implement application control policies to restrict the ability of users to load configuration files from non-standard or external locations.</li>
<li>Monitor for GIMP process crashes or unexpected termination events which may indicate exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>memory-corruption</category><category>cve-2026-97185</category></item></channel></rss>