← All Advisories

CVE-2026-6384

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-6384

Key Details

CVECVE-2026-6384
CVSS Score / Version7.3 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Enterprise Linux, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, and gimp gimp
Classified asCWE-120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 6
gimpgimp
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution. (NVD)

What to Do

Monitor Red Hat's and gimp's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-6384
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-6384
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-6384