CVE-2026-59090: Integer Underflow (Wrap or Wraparound) in Red Hat Red Hat Enterprise Linux 6
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.
AI Analysis
Technical Summary
CVE-2026-59090 is an unsigned integer underflow vulnerability in the block_rem variable of GIMP's PSD file format plugin. When a user opens a maliciously crafted .psd file, the underflow causes parser confusion that allows injection of arbitrary data as layer resource blocks. This can lead to arbitrary code execution on the affected system. The vulnerability affects Red Hat Enterprise Linux 6 where GIMP is installed. The CVSS v3.1 score is 8.4 (High), reflecting network attack vector, high attack complexity, low privileges required, no user interaction, and impacts on confidentiality, integrity, and availability. No official patch or fix status is provided in the vendor advisory, but mitigation involves avoiding untrusted PSD files.
Potential Impact
Successful exploitation can lead to arbitrary code execution, allowing attackers to run malicious code on the victim's system. The vulnerability impacts confidentiality, integrity, and availability, with potential for system crashes or instability due to the integer underflow. The attack requires low privileges and no user interaction but has high attack complexity. This primarily affects desktop environments processing untrusted PSD files with GIMP.
Mitigation Recommendations
Red Hat's advisory recommends avoiding opening untrusted or suspicious PSD image files with GIMP to mitigate this vulnerability. No official patch or fix has been confirmed yet. Users should follow vendor guidance and monitor the Red Hat advisory for updates regarding patches or official fixes.
CVE-2026-59090: Integer Underflow (Wrap or Wraparound) in Red Hat Red Hat Enterprise Linux 6
Description
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.
CVSS v3.1
Score 8.4high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-59090 is an unsigned integer underflow vulnerability in the block_rem variable of GIMP's PSD file format plugin. When a user opens a maliciously crafted .psd file, the underflow causes parser confusion that allows injection of arbitrary data as layer resource blocks. This can lead to arbitrary code execution on the affected system. The vulnerability affects Red Hat Enterprise Linux 6 where GIMP is installed. The CVSS v3.1 score is 8.4 (High), reflecting network attack vector, high attack complexity, low privileges required, no user interaction, and impacts on confidentiality, integrity, and availability. No official patch or fix status is provided in the vendor advisory, but mitigation involves avoiding untrusted PSD files.
Potential Impact
Successful exploitation can lead to arbitrary code execution, allowing attackers to run malicious code on the victim's system. The vulnerability impacts confidentiality, integrity, and availability, with potential for system crashes or instability due to the integer underflow. The attack requires low privileges and no user interaction but has high attack complexity. This primarily affects desktop environments processing untrusted PSD files with GIMP.
Mitigation Recommendations
Red Hat's advisory recommends avoiding opening untrusted or suspicious PSD image files with GIMP to mitigate this vulnerability. No official patch or fix has been confirmed yet. Users should follow vendor guidance and monitor the Red Hat advisory for updates regarding patches or official fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-02T15:11:12.821Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-59090","vendor":"Red Hat"}]
Threat ID: 6a79c3abbf8831d539a740f5
Added to database: 08/10/2026, 12:27:23 UTC
Last enriched: 08/10/2026, 12:42:02 UTC
Last updated: 08/10/2026, 20:05:20 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.