CVE-2026-6695

MEDIUM CVSS 3.1: 5.5 EPSS 0.15%
Updated Aug 03, 2026
Red Hat
Parameter Value
CVSS 5.5 (MEDIUM)
Type CWE-805
Vendor Red Hat
Public PoC No

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer.

This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat enterprise linux 7 red hat:red hat enterprise linux 9 red hat:red hat enterprise linux 6 red hat:red hat enterprise linux 8