CVE-2026-58379EPSS p14.4%
CVE-2026-58379CVE-2026-58379
Description
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.
Scoring
| CVSS | 7.3 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.23% probability of exploitation · percentile 14.4% · 2026-08-17T12:03:47Z |
| Last modified | 2026-07-13 |