CVE-2026-90947: Red Hat Enterprise Linux 6
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to open a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
Affected products
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 2:3.0.4-4.el9_8.14 (fixed in 2:3.0.4-4.el9_8.14)
Published 2026-09-14. Last modified 2026-10-05.