GIMP 的 PSP(Paint Shop Pro)文件加载器中存在一个缺陷。在处理压缩的选择通道时,由于分配的缓冲区大小与解压后的数据量不匹配,可能会发生堆缓冲区溢出。远程攻击者可以通过构造一个恶意的 PSP 文件来利用此漏洞。在 GIMP 中打开该文件时,可能导致程序崩溃或任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90947 | 7.8 HIGH | Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file |
| CVE-2026-90948 | 7.8 HIGH | Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png |
| CVE-2026-90995 | 5.5 MEDIUM | Sssd: sssd: local denial of service due to null pointer dereference in pam responder |
| CVE-2026-90996 | 4.0 MEDIUM | Sssd: sssd: denial of service in nss responder via crafted zero-length requests |
| CVE-2026-90994 | 4.0 MEDIUM | Sssd: sssd: denial of service via malformed pam v1 requests |
| CVE-2026-90463 | 4.0 MEDIUM | Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / ` |
No comments yet