A flaw was found in the file-psd plugin in GIMP. (CVE-2026-92248)
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution.
AI Analysis
Technical Summary
CVE-2026-92248 is a vulnerability in the GIMP file-psd plugin where an integer overflow during thumbnail preview generation of a crafted PSD file causes an undersized heap allocation. This results in a heap-based buffer overflow when decoding image data, corrupting adjacent heap objects and enabling controlled memory writes. The flaw is triggered automatically when the GIMP file chooser previews PSD files, without needing to open them. Exploitation requires local user interaction and can lead to application crashes or arbitrary code execution. Red Hat's advisory highlights the role of default security mitigations in reducing exploitability and recommends avoiding untrusted PSD directories and disabling thumbnail previews as mitigations.
Potential Impact
The vulnerability allows local attackers to cause application crashes or potentially execute arbitrary code by exploiting a heap-based buffer overflow triggered during thumbnail generation of PSD files. The attack vector is local with user interaction required. Default security mechanisms such as SELinux enforcement, ASLR, and NX stack protection significantly reduce the likelihood of successful arbitrary code execution. The impact includes high confidentiality, integrity, and availability consequences if exploited.
Mitigation Recommendations
Red Hat advises users to avoid navigating to directories containing PSD files from untrusted sources using the GIMP file chooser. Additionally, users can disable thumbnail generation in GIMP preferences to prevent the vulnerable code path from being executed. These mitigations reduce exposure until an official fix is available. Patch status is not confirmed in the provided data; check the vendor advisory for updates.
A flaw was found in the file-psd plugin in GIMP. (CVE-2026-92248)
Description
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution.
CVSS v3.1
Score 7.8high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92248 is a vulnerability in the GIMP file-psd plugin where an integer overflow during thumbnail preview generation of a crafted PSD file causes an undersized heap allocation. This results in a heap-based buffer overflow when decoding image data, corrupting adjacent heap objects and enabling controlled memory writes. The flaw is triggered automatically when the GIMP file chooser previews PSD files, without needing to open them. Exploitation requires local user interaction and can lead to application crashes or arbitrary code execution. Red Hat's advisory highlights the role of default security mitigations in reducing exploitability and recommends avoiding untrusted PSD directories and disabling thumbnail previews as mitigations.
Potential Impact
The vulnerability allows local attackers to cause application crashes or potentially execute arbitrary code by exploiting a heap-based buffer overflow triggered during thumbnail generation of PSD files. The attack vector is local with user interaction required. Default security mechanisms such as SELinux enforcement, ASLR, and NX stack protection significantly reduce the likelihood of successful arbitrary code execution. The impact includes high confidentiality, integrity, and availability consequences if exploited.
Mitigation Recommendations
Red Hat advises users to avoid navigating to directories containing PSD files from untrusted sources using the GIMP file chooser. Additionally, users can disable thumbnail generation in GIMP preferences to prevent the vulnerable code path from being executed. These mitigations reduce exposure until an official fix is available. Patch status is not confirmed in the provided data; check the vendor advisory for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v7fc-wcg3-84gx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-92248"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aaa07ab55bf5e2cf5e88ba5
Added to database: 09/16/2026, 03:06:19 UTC
Last enriched: 09/16/2026, 03:09:08 UTC
Last updated: 09/17/2026, 03:01:24 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.