CVE-2026-78465 – GNOME GIMP

CVSS 7 IMPORTANT Zero Day – Immediate Deployment

“A crafted PCX image can corrupt memory in 32-bit GIMP builds and potentially lead to code execution.”

GIMP is affected by a High-severity integer overflow in the PCX image plugin on 32-bit builds. CVE-2026-78465 allows a crafted PCX file to trigger an undersized heap allocation, followed by a heap-based buffer overflow when image data is written. This can cause memory corruption, denial of service, or potentially arbitrary code execution. The CVSS score is 7.0, which is High severity.

Public proof-of-concept material is available for the vulnerability.

Key Details

Affected Product
Gimp Gimp
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-190
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.