A flaw was found in GIMP's PSD file format plugin. This...
High severity
Unreviewed
Published
Aug 10, 2026
to the GitHub Advisory Database
•
Updated Aug 10, 2026
Description
Published by the National Vulnerability Database
Aug 10, 2026
Published to the GitHub Advisory Database
Aug 10, 2026
Last updated
Aug 10, 2026
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the
block_remvariable, occurs when a user opens a specially crafted.psdimage file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.References