---
id: CVE-2025-48798
title: A flaw was found in GIMP when processing XCF image files
summary: >-
  A flaw was found in GIMP when processing XCF image files. If a user opens one
  of these image files that has been specially crafted by an attacker, GIMP can
  be tricked into making serious memory errors, potentially leading to crashes
  and …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
published: '2025-05-27'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48798'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:9162'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9165'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9308'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9309'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9310'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9314'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9315'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9316'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9501'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9569'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-48798'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2368557'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/gimp/-/issues/11822'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2025/10/msg00022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00231
epssPercentile: 0.12499
ingestedAt: '2026-06-29T13:24:34.343Z'
---

## Overview

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
