Heap-based buffer overflow in Gimp - CVE-2026-4152
Published: March 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote attacker can trick a victim to open a specially crafted JP2 file, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
openEuler
gimp-debuginfo
gimp-debugsource
gimp-devel
gimp-help
gimp-libs
gimp
gimp (Debian package)
gimp-plugin-python3
gimp-extension-goat-excercises
gimp-plugin-aa
gimp-vala
How to mitigate CVE-2026-4152
gimp-debugsource - addressed in versions 2.10.6-20, 3.0.2-11
gimp-devel - addressed in versions 2.10.6-20, 3.0.2-11
gimp-help - update to 2.10.6-20
gimp-libs - addressed in versions 2.10.6-20, 3.0.2-11
gimp - addressed in versions 2.10.6-20, 3.0.2-11
gimp (Debian package) - addressed in versions 2.10.34-1+deb12u10, 3.0.4-3+deb13u8
gimp-plugin-python3 - update to 3.0.2-11
gimp-extension-goat-excercises - update to 3.0.2-11
gimp-plugin-aa - update to 3.0.2-11
gimp-vala - update to 3.0.2-11