CVE-2026-59091 – Red Hat Enterprise Linux 6 / GIMP
“A malicious image can turn routine file handling into code execution or memory corruption.”
GIMP components distributed with Red Hat Enterprise Linux 6 are affected by four vulnerabilities involving unsafe image-file processing. CVE-2026-59090 has a CVSS score of 8.4, High severity and can lead to arbitrary code execution through a crafted PSD file. CVE-2026-59087 has a CVSS score of 7.8, High severity and can cause memory corruption, code execution, or denial of service. CVE-2026-59091 has a CVSS score of 7.3, High severity and affects PSD and PAA file processing.
CVE-2026-59088 has a CVSS score of 5.5, Medium severity and can cause denial of service when a crafted FLI file triggers an integer overflow. Public proof-of-concept information is available for CVE-2026-59090.
Key Details
- Affected Product
- Gimp Gimp
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- Required
- CWE Classification
- CWE-787