Status: UPDATED
| Advisory ID: CVE-2026-58384
Key Details
| CVE | CVE-2026-58384 |
| CVSS Score / Version | 7.3 (High) / CVSS v3.1 |
| Updated | 2026-09-30 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Enterprise Linux, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support, and gimp gimp |
| Classified as | CWE-190 (Integer Overflow or Wraparound) |
Affected Products, Subsystems & Sectors
| Subsystems | OT Supporting Infrastructure |
| Sectors | All Sectors |
What to Know
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. (NVD)
What to Do
Monitor Red Hat's and gimp's web pages for any future patch releases. See vendor advisory link below.
References