{"id":"CVE-2026-58381","title":"A flaw was found in GIMP's PSP file format parser","summary":"A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leadi…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","cwe":["CWE-415"],"vendor":"gimp","product":"gimp","affected":["gimp <= 3.2.1","enterprise_linux = 6.0","enterprise_linux = 7.0","enterprise_linux = 8.0","enterprise_linux = 9.0"],"published":"2026-07-02","updated":"2026-09-22","sourceUpdated":"2026-09-22T15:21:43.420","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-58381","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-58381","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2496166","label":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/gimp/-/commit/b22e147b","label":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/gimp/-/issues/16207","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58381.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-58381"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58381"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00118,"epssPercentile":0.01948,"ingestedAt":"2026-09-22T16:06:00.457Z","slug":"CVE-2026-58381","body":"## Overview\n\nA flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.\n\n## Affected\n\n- `gimp <= 3.2.1`\n- `enterprise_linux = 6.0`\n- `enterprise_linux = 7.0`\n- `enterprise_linux = 8.0`\n- `enterprise_linux = 9.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58381.json)","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}