PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58379 Red Hat CVE debrief

A high-severity vulnerability was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows remote attackers to cause arbitrary code execution or a denial of service (DoS) by tricking users into opening specially crafted PSP image files. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory. Users and administrators should be cautious when handling PSP image files from untrusted sources.

Vendor
Red Hat
Product
Red Hat Enterprise Linux 6
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-03
Original CVE updated
2026-07-13
Advisory published
2026-07-03
Advisory updated
2026-07-13

Who should care

Users and administrators of GIMP, especially those handling PSP image files from untrusted sources, should be aware of this vulnerability and take necessary precautions. This includes updating GIMP to a patched version and being cautious when opening PSP image files from unknown sources. Security teams should review their monitoring and detection capabilities to identify potential exploitation attempts.

Technical summary

The vulnerability occurs because GIMP's PSP file format parser incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory. This can be exploited by remote attackers to execute arbitrary code or cause a denial of service. The PSP file format parser does not properly handle certain image file parameters, allowing attackers to craft malicious files that trigger the vulnerability.

Defensive priority

High priority should be given to updating GIMP to a version that patches this vulnerability, especially in environments where PSP image files are frequently processed. Additional security measures such as monitoring and intrusion detection should be implemented to detect potential exploitation attempts.

Recommended defensive actions

  • Update GIMP to the latest version that patches this vulnerability
  • Be cautious when opening PSP image files from untrusted sources
  • Implement additional security measures such as monitoring and intrusion detection
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-07-03T19:16:37.040Z and last modified on 2026-07-07T18:16:39.700Z. The NVD entry is currently Awaiting Analysis. This vulnerability affects GIMP's Paint Shop Pro (PSP) file format parser, allowing remote attackers to cause arbitrary code execution or a denial of service (DoS). Evidence is limited, and defenders should verify PSP image file handling and user interaction.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58379 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58379

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58379 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58379

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.