Ad

CVE-2026-40918

MEDIUM CVSS 3.1: 5.5
Updated Apr 17, 2026
GIMP
Parameter Value
CVSS 5.5 (MEDIUM)
Type CWE-131
Vendor GIMP
Public PoC No

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash.

Systems that process untrusted PVR image files are affected.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)