Skip to main content
EPSS 0.2%top 92%

A flaw was found in the file-psd plugin in GIMP. (CVE-2026-92248)

0
High
Published: 09/16/2026 (09/16/2026, 00:31:32 UTC)
Source: GCVE Database

Description

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution.

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/16/2026, 03:09:08 UTC

Technical Analysis

CVE-2026-92248 is a vulnerability in the GIMP file-psd plugin where an integer overflow during thumbnail preview generation of a crafted PSD file causes an undersized heap allocation. This results in a heap-based buffer overflow when decoding image data, corrupting adjacent heap objects and enabling controlled memory writes. The flaw is triggered automatically when the GIMP file chooser previews PSD files, without needing to open them. Exploitation requires local user interaction and can lead to application crashes or arbitrary code execution. Red Hat's advisory highlights the role of default security mitigations in reducing exploitability and recommends avoiding untrusted PSD directories and disabling thumbnail previews as mitigations.

Potential Impact

The vulnerability allows local attackers to cause application crashes or potentially execute arbitrary code by exploiting a heap-based buffer overflow triggered during thumbnail generation of PSD files. The attack vector is local with user interaction required. Default security mechanisms such as SELinux enforcement, ASLR, and NX stack protection significantly reduce the likelihood of successful arbitrary code execution. The impact includes high confidentiality, integrity, and availability consequences if exploited.

Mitigation Recommendations

Red Hat advises users to avoid navigating to directories containing PSD files from untrusted sources using the GIMP file chooser. Additionally, users can disable thumbnail generation in GIMP preferences to prevent the vulnerable code path from being executed. These mitigations reduce exposure until an official fix is available. Patch status is not confirmed in the provided data; check the vendor advisory for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-v7fc-wcg3-84gx
Osv Schema Version
1.4.0
Aliases
["CVE-2026-92248"]
Database Specific Severity
HIGH
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aaa07ab55bf5e2cf5e88ba5

Added to database: 09/16/2026, 03:06:19 UTC

Last enriched: 09/16/2026, 03:09:08 UTC

Last updated: 09/17/2026, 03:01:24 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses