ZeroHour

CVE-2026-90947

mass

Out-of-Bounds Write in GIMP Lighting Effects Filter via Malicious Preset Files

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

GIMP's Lighting Effects filter fails to validate the number of light sources when loading a lighting preset file, allowing a specially crafted preset to trigger an out-of-bounds write and corrupt memory. The flaw is exploited through social engineering: an attacker must convince a user to open a malicious preset file, after which the bug can crash GIMP or potentially enable arbitrary code execution with the user's privileges. All users of affected GIMP versions who open untrusted lighting presets are at risk; the CVSS 3.1 base score is 7.8 (high) with a local attack vector requiring user interaction. No public proof-of-concept is known, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and there are no reports of in-the-wild exploitation.

What to do: Update GIMP as soon as a patched release is issued by the GIMP project or your Linux distribution, since no fixed version is named in the advisory. In the meantime, do not open lighting preset files (Lighting Effects filter presets) received from untrusted or unknown sources, and treat preset files shared in forums or tutorials with caution. If the Lighting Effects filter is not needed in your environment, consider restricting its use and running GIMP under an unprivileged user account to limit the impact of potential code execution.

Affected
GIMP (Lighting Effects filter)
Estimated exposure
massOrder of magnitude: millions of desktop installations worldwide (plausibly tens of millions including Linux distro bundles) — GIMP is a widely deployed free, open-source image editor shipped by default or via standard repositories on most Linux distributions and downloaded millions of times on Windows/macOS; however, practical exposure is limited to users who…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to open a malicious preset file, potentially causing a crash or enabling arbitrary code execution.

Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.