← All Advisories

CVE-2026-59090

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-59090

Key Details

CVECVE-2026-59090
CVSS Score / Version8.4 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is low; user interaction is none; scope is changed; confidentiality impact is low; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-191 (Integer Underflow (Wrap or Wraparound))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat Enterprise Linux 7
gimpgimp
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system. (NVD)

What to Do

Monitor Red Hat's and gimp's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-59090
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-59090
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-59090