{"schema_version":"1.7.5","id":"CVE-2026-4150","published":"2026-04-11T00:15:36.377Z","modified":"2026-07-22T03:22:01.493919Z","related":["ALSA-2026:16484","ALSA-2026:17533","ALSA-2026:19362","SUSE-SU-2026:1193-1","openSUSE-SU-2026:20428-1"],"summary":"GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability","details":"GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28807.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/gimp","events":[{"introduced":"6ac8031c9555667e080fef0324fca9f28a02e5ab"},{"last_affected":"6ac8031c9555667e080fef0324fca9f28a02e5ab"}],"database_specific":{"cpe":"cpe:2.3:a:gimp:gimp:3.0.8:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0.8"},{"last_affected":"3.0.8"}],"source":"CPE_STRING"}},{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/gimp","events":[{"introduced":"6ac8031c9555667e080fef0324fca9f28a02e5ab"},{"fixed":"00afdabdadeb5457fd897878b1e5aebc3780af10"}],"database_specific":{"cpe":"cpe:2.3:a:gimp:gimp:3.0.8:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0.8"},{"last_affected":"3.0.8"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["3.0.8","GIMP_3_0_8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4150.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"231743745706218230515386684289989053851","length":566},"id":"CVE-2026-4150-945b7ad1","signature_type":"Function","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/gimp@00afdabdadeb5457fd897878b1e5aebc3780af10","target":{"file":"plug-ins/file-psd/psd-load.c","function":"decode_32_bit_predictor"}},{"deprecated":false,"digest":{"line_hashes":["185470298734061008067996902855312543459","280199743358454446229740620687448080551","194812579991233889530227554620865539186","315469437345368785851130652367228525149","253500943787404771472358550270547689646","101038232722397977123632047161684816764","319660422576595669755232106634121758143","97950234393733278922517965663044789153","323844305400148153029537347113978581336","293581638887017815333178723657774381715","15969743184858499888700142979654041512","112076168346913636230933901480221712494","242575763342019549067362200799371711375","177525053505564129421555136510865995175","159083012890127839649988608850546961719","241304465527151298281061221371324642291","153575913268275128000086873006386625526","245520921606102554167201471490946304380","327570147816400176795917709210251346976","193185599725366322649383055258558614487","101453589471538021237813609091676707346","190411889703073688514682647234481475454","298666331875010114021237003099605785152","188805824161113237197183684676111022558","168679232364005536160798456342928996724","305852668529899424795154590760769426568","22455492810798714811610894880157659082","146153772375376500755207430066201208996","100484354090346142753156077424534298070","67427093205174645838335853507039950220","139520482421890035302808687015089259702","147028763123962855028694844199049789357","330678326378740358565818295476756972712","169646878283121492795388740656571770576","237439359848622032662430039247421063604","237861511124868128586563982524126992003","13184112499892600358926789546973252734","190715481461204614796521518326514332144","147574813524722534029991571130897676405","121673902505721516460735978637441206767","215048091886899674494785134820866763188","66565826916895088070508879295430435302","29436378659575917773603090036872717344","39721376603973759799443120770914168818","40628565239078444907274601035493871193","103536512252938691399266797899065851559","298786347563453391854112960117069905798","231073538678456150841044127432548863937","186745823683843144745522013830667801643","40308998506158398102643536780185145462","271145949958856886157892023617454522427","258138608717186705423706955700093133262","61622632241208853439656758633627008932","227853828843025392517114208655482089404","212620651672958254888144590206943599781","143424421273006798525222027532279459927","347453186772633232417085265557472755","152576617476277433638903288264921386620","163899062802756372141929054529156936554","314913419506067002198074325337514805439","205964604707673691478959745229649220765","251299788812648674116584998482068474209","89923271379368432208194636472359671920","164446007902321750192915786658703584384","294846146936644910439846453848714604828","200695858261873200564672399454212536773","235814716118854954490575315823588887654","77517447858909563030270729779163266634","238773528738481340540116457816613558440","306977872566049952334615044653424002402","1082529252789827122150963466543485201","339078593779650162798617306252537518440","161375952811288338149170256330446687512","103246778082588306815386663806393791904","127918430135413445047703876741358224013","230542846554467181063642978997138162657","106922953437722533270783990018837524094","33359172189090764059240495695751712110","4953571176865109769228050866267093556","9280775726876775407663628005687258512","37493204146913067472808611373377170378","189162412561066150712921879423947663352","127069311101163082133271943865065665759","120581048969102786385140326374024256466","325979336880416497404157873350289558092","123577752989243417215350251803248434401","177635698049091647678376168843464213683","254604091551905991089742542775938348168","68882945317528210685333140414922941326"],"threshold":0.9},"id":"CVE-2026-4150-a0052a57","signature_type":"Line","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/gimp@00afdabdadeb5457fd897878b1e5aebc3780af10","target":{"file":"plug-ins/file-psd/psd-load.c"}},{"deprecated":false,"digest":{"function_hash":"136978649341436418523872070030571995045","length":7500},"id":"CVE-2026-4150-cd0117a1","signature_type":"Function","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/gimp@00afdabdadeb5457fd897878b1e5aebc3780af10","target":{"file":"plug-ins/file-psd/psd-load.c","function":"add_merged_image"}},{"deprecated":false,"digest":{"function_hash":"70062601879146340225677562179843432994","length":3580},"id":"CVE-2026-4150-de4e9b9d","signature_type":"Function","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/gimp@00afdabdadeb5457fd897878b1e5aebc3780af10","target":{"file":"plug-ins/file-psd/psd-load.c","function":"read_channel_data"}},{"deprecated":false,"digest":{"function_hash":"218256817996083841272752021730205960487","length":590},"id":"CVE-2026-4150-ebf85cd4","signature_type":"Function","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/gimp@00afdabdadeb5457fd897878b1e5aebc3780af10","target":{"file":"plug-ins/file-psd/psd-load.c","function":"convert_1_bit"}}],"vanir_signatures_modified":"2026-07-22T03:22:01Z"}}],"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4150.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16484"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17533"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19362"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:20552"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:20553"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:20554"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:20691"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25899"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25901"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25907"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26168"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-4150"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4150.json"},{"type":"ADVISORY","url":"https://gitlab.gnome.org/GNOME/gimp/-/commit/00afdabdadeb5457fd897878b1e5aebc3780af10"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4150"},{"type":"ADVISORY","url":"https://www.zerodayinitiative.com/advisories/ZDI-26-217/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2457535"}],"database_specific":{"cna_assigner":"zdi","cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4150.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}