PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58381 Red Hat CVE debrief

A flaw in GIMP's PSP file format parser could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution. The CVE record was published on 2026-07-02T20:17:06.170Z and was last modified on 2026-09-22T15:21:43.420Z. The NVD entry is currently Analyzed. Defenders responsible for GIMP installations, especially in environments where untrusted PSP files may be processed, should assess exposure and prioritize verification and patching. This vulnerability is caused by a double-free condition in the read_layer_block() function when processing a specially crafted PSP file.

Vendor
Red Hat
Product
Red Hat Enterprise Linux 6
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-02
Original CVE updated
2026-09-22
Advisory published
2026-07-02
Advisory updated
2026-09-22

Who should care

Defenders responsible for GIMP installations, especially in environments where untrusted PSP files may be processed, should assess exposure and prioritize verification and patching.

Why it matters

A flaw in GIMP's PSP file format parser could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution. Defenders should prioritize verifying exposure in GIMP installations, especially in environments where untrusted PSP files may be processed, and apply patches or updates as available.

  • Potential denial of service due to memory corruption.
  • Possible arbitrary code execution if exploitation is successful.
  • Verification of GIMP installations and PSP file processing environments is necessary.
  • Patching or updating GIMP to a secure version is required.

Technical summary

A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file, potentially leading to memory corruption. This vulnerability affects GIMP installations, especially in environments where untrusted PSP files may be processed. The CVE record and NVD detail page provide information about the vulnerability, but do not provide specific affected versions beyond GIMP 3.2.1. Defenders should prioritize verifying exposure in GIMP installations and apply patches or updates as available.

Defensive priority

Defenders should prioritize verifying exposure in GIMP installations, especially in environments where untrusted PSP files may be processed.

Recommended defensive actions

  • Verify GIMP installations for exposure, especially in environments where untrusted PSP files may be processed.
  • Apply patches or updates to GIMP as available.
  • Monitor GIMP logs for suspicious activity.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD detail page provide information about the vulnerability, but do not provide evidence of exploitation or specific affected versions beyond GIMP 3.2.1. There is no information on publicly available exploits or reports of exploitation. Defenders should verify GIMP installations, especially in environments where untrusted PSP files may be processed, and apply patches or updates as available. The official CVE Program record and NVD detail page are provided as references.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58381 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58381

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58381 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58381

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.