CVE-2026-90947
massOut-of-Bounds Write in GIMP Lighting Effects Filter via Malicious Preset Files
GIMP's Lighting Effects filter fails to validate the number of light sources when loading a lighting preset file, allowing a specially crafted preset to trigger an out-of-bounds write and corrupt memory. The flaw is exploited through social engineering: an attacker must convince a user to open a malicious preset file, after which the bug can crash GIMP or potentially enable arbitrary code execution with the user's privileges. All users of affected GIMP versions who open untrusted lighting presets are at risk; the CVSS 3.1 base score is 7.8 (high) with a local attack vector requiring user interaction. No public proof-of-concept is known, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and there are no reports of in-the-wild exploitation.
What to do: Update GIMP as soon as a patched release is issued by the GIMP project or your Linux distribution, since no fixed version is named in the advisory. In the meantime, do not open lighting preset files (Lighting Effects filter presets) received from untrusted or unknown sources, and treat preset files shared in forums or tutorials with caution. If the Lighting Effects filter is not needed in your environment, consider restricting its use and running GIMP under an unprivileged user account to limit the impact of potential code execution.
| GIMP (Lighting Effects filter) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to open a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.