Description
A flaw was found in GIMP. The XCF loader processes image-simulation-intent and image-simulation-bpc parasites without ensuring the parasite data is present before dereferencing it. Opening a specially crafted XCF file with a zero-size simulation parasite can cause a NULL pointer dereference and crash the GIMP application.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Do not open untrusted XCF files with GIMP.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 09 Oct 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gimp
Gimp gimp |
|
| Vendors & Products |
Gimp
Gimp gimp |
Fri, 09 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in GIMP. The XCF loader processes image-simulation-intent and image-simulation-bpc parasites without ensuring the parasite data is present before dereferencing it. Opening a specially crafted XCF file with a zero-size simulation parasite can cause a NULL pointer dereference and crash the GIMP application. | |
| Title | Gimp: gimp: denial of service via null pointer dereference in xcf simulation parasite loading | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-09T16:45:57.667Z
Reserved: 2026-10-09T13:14:50.850Z
Link: CVE-2026-108093
No data.
Status : Awaiting Analysis
Published: 2026-10-09T17:16:46.260
Modified: 2026-10-09T17:42:00.023
Link: CVE-2026-108093
No data.
OpenCVE Enrichment
Updated: 2026-10-09T19:00:15Z
Weaknesses