CVE-2026-97185: Red Hat Enterprise Linux 10
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 2:3.0.4-4.el9_8.14 (fixed in 2:3.0.4-4.el9_8.14)
Published 2026-09-24. Last modified 2026-10-05.