Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82343— Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 6
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GIMP 的 file-psd 插件中存在一个缺陷。在处理一个精心构造的 PSD 图像文件时,该插件未对通道数量(channel-count)参数进行正确校验。这种不正确的校验会导致内存边界检查不当,从而引发堆内存越界读取和栈内存越界访问。该问题可能导致应用程序崩溃,进而造成服务拒绝(DoS),或导致内存内容被有限地泄露。

CVSS 6.1 · Medium

Affected Version Matrix 4

VendorProduct Version RangeStatus
Red Hat Red Hat Enterprise Linux 6 any unknown
Red Hat Red Hat Enterprise Linux 7 any affected
Red Hat Red Hat Enterprise Linux 8 any affected
Red Hat Red Hat Enterprise Linux 9 any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82343

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of memory contents.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-82343

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82343

登录查看更多情报信息。

Vendor Advisories for CVE-2026-82343 (1)

Vendor Pages for CVE-2026-82343 (1)

Other References for CVE-2026-82343 (1)

Same Patch Batch · Red Hat · 2026-08-28 · 6 CVEs total

CVE-2026-82330 6.1 MEDIUM Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check
CVE-2026-82328 6.1 MEDIUM Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count
CVE-2026-82324 6.1 MEDIUM Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0
CVE-2026-82327 5.5 MEDIUM Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from ve
CVE-2026-18393 5.4 MEDIUM Ffmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono cursor

IV. Related Vulnerabilities

V. Comments for CVE-2026-82343

No comments yet


Leave a comment