CVE-2026-58379: Red Hat Enterprise Linux 6
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.
Affected products
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 2:3.0.4-4.el9_8.5 (fixed in 2:3.0.4-4.el9_8.5)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 2:2.99.8-4.el9_6.20 (fixed in 2:2.99.8-4.el9_6.20)
Published 2026-07-03. Last modified 2026-09-30.