A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 22:17
Updated : 2026-09-15 22:17
NVD link : CVE-2026-92248
Mitre link : CVE-2026-92248
CVE.ORG link : CVE-2026-92248
JSON object : View
Products Affected
No product.
CWE
CWE-190
Integer Overflow or Wraparound
