Ad

CVE-2026-2271

LOW CVSS 3.1: 3.3 EPSS 0.14%
Updated Mar 30, 2026
GIMP
Parameter Value
CVSS 3.3 (LOW)
Type CWE-190 (Integer Overflow)
Vendor GIMP
Public PoC No

A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for memory allocation without proper validation, leading to a heap overflow and an out-of-bounds write.

Successful exploitation could result in an application level denial of service.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Weakness Type (CWE)