GIMP 中的 file-psd 插件存在一个缺陷。在为精心构造的 PSD(Photoshop Document)图像文件生成缩略图预览时,在解析内嵌 JPEG 头部中的数值进行乘法运算时发生整数溢出。这导致了堆分配内存不足,进而当图像数据被解码时引发基于堆的缓冲区溢出。该缓冲区溢出会破坏相邻的堆对象,从而实现受控的内存写入,可能导致应用程序崩溃或任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85234 | 7.5 HIGH | Tftp: tftp-hpa: denial of service due to out-of-bounds read/write in remap engine |
| CVE-2026-75092 | 7.3 HIGH | Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld |
| CVE-2026-85013 | 7.3 HIGH | Environment-modules: command injection in environment-modules bash completion via maliciou |
| CVE-2026-81303 | 6.3 MEDIUM | Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostnam |
| CVE-2026-91786 | 6.1 MEDIUM | Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvali |
| CVE-2026-81320 | 5.5 MEDIUM | Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level |
| CVE-2025-11395 | 5.5 MEDIUM | Podman: arbitrary file write when importing oci archive |
| CVE-2026-79705 | 4.5 MEDIUM | Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outsi |
| CVE-2026-79699 | 4.4 MEDIUM | Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacem |
| CVE-2026-91926 | 3.7 LOW | Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair en |
No comments yet