CVE-2026-2272: Gimp
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for image buffers can wrap around due to a 32-bit integer evaluation, allowing oversized image headers to bypass security checks. A remote attacker could exploit this by providing a specially crafted ICO file, leading to a buffer overflow and memory corruption, which may result in an application level denial of service.
Affected products
- Gimp Gimp: version 3.0.6 only
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 9.0 only
Published 2026-03-26. Last modified 2026-06-17.