CVE-2026-58380
This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.26% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-193
- Affected
- gimp/gimp · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2026:40751
- https://access.redhat.com/errata/RHSA-2026:62507
- https://access.redhat.com/security/cve/CVE-2026-58380Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2496135Issue Tracking, Third Party Advisory
- https://gitlab.gnome.org/GNOME/gimp/-/commit/83699817Broken Link
- https://gitlab.gnome.org/GNOME/gimp/-/issues/16206Exploit, Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.