CVE-2026-97185: Red Hat Enterprise Linux 10

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 2:3.0.4-4.el9_8.14 (fixed in 2:3.0.4-4.el9_8.14)

Published 2026-09-24. Last modified 2026-10-05.