{"advisories":[{"id":"DSA-6470-1","source":"dsa","title":"gimp security update","url":"https://lists.debian.org/debian-security-announce/2026/msg00381.html"}],"cve":"CVE-2026-58381","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":null}],"enrichment":{"confidence":100.0,"confidence_source":"manual","scores":[{"score":100.0,"source":"manual"}]},"product":"gimp","vendor":"gimp"},{"configurations":[{"platform":null,"status":"affected","versions":null}],"enrichment":{"confidence":100.0,"confidence_source":"manual","scores":[{"score":100.0,"source":"manual"}]},"original":{"product":"Red Hat Enterprise Linux 6","source":"cna","vendor":"Red Hat"},"product":"enterprise_linux","vendor":"redhat"}],"created":"2026-07-03T06:15:03.345300+00:00","updated":"2026-08-01T21:15:04.727858+00:00","vendors":["gimp","gimp$PRODUCT$gimp","redhat","redhat$PRODUCT$enterprise_linux"]},"epss":{"score":0.00289},"mitre":{"cpes":["cpe:/o:redhat:enterprise_linux:6","cpe:/o:redhat:enterprise_linux:7","cpe:/o:redhat:enterprise_linux:8","cpe:/o:redhat:enterprise_linux:9"],"created":"2026-07-02T19:45:33.777000+00:00","description":"A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":6.1,"vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/58xxx/CVE-2026-58381.json","references":["https://access.redhat.com/security/cve/CVE-2026-58381","https://bugzilla.redhat.com/show_bug.cgi?id=2496166","https://gitlab.gnome.org/GNOME/gimp/-/commit/b22e147b","https://gitlab.gnome.org/GNOME/gimp/-/issues/16207"],"title":"Gimp: gimp: double-free in read_layer_block()","updated":"2026-07-07T17:02:18.749000+00:00","vendors":["redhat","redhat$PRODUCT$enterprise_linux"],"weaknesses":["CWE-415"]},"nvd":{"cpes":["cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*"],"created":"2026-07-02T20:17:06.170000+00:00","description":"A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":6.1,"vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-58381.json","references":["https://access.redhat.com/security/cve/CVE-2026-58381","https://bugzilla.redhat.com/show_bug.cgi?id=2496166","https://gitlab.gnome.org/GNOME/gimp/-/commit/b22e147b","https://gitlab.gnome.org/GNOME/gimp/-/issues/16207"],"title":null,"updated":"2026-09-22T15:21:43.420000+00:00","vendors":["gimp","gimp$PRODUCT$gimp","redhat","redhat$PRODUCT$enterprise_linux"],"weaknesses":["CWE-415"]},"opencve":{"changes":[{"created":"2026-07-02T20:15:00+00:00","data":[{"details":{"new":"A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.","old":null},"type":"description"},{"details":{"new":"Gimp: gimp: double-free in read_layer_block()","old":null},"type":"title"},{"details":["redhat","redhat$PRODUCT$enterprise_linux"],"type":"first_time"},{"details":{"added":["CWE-415"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:/o:redhat:enterprise_linux:6","cpe:/o:redhat:enterprise_linux:7","cpe:/o:redhat:enterprise_linux:8","cpe:/o:redhat:enterprise_linux:9"],"removed":[]},"type":"cpes"},{"details":{"added":["redhat","redhat$PRODUCT$enterprise_linux"],"removed":[]},"type":"vendors"},{"details":{"added":["https://access.redhat.com/security/cve/CVE-2026-58381","https://bugzilla.redhat.com/show_bug.cgi?id=2496166","https://gitlab.gnome.org/GNOME/gimp/-/commit/b22e147b","https://gitlab.gnome.org/GNOME/gimp/-/issues/16207"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":6.1,"vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"311c6703-2152-4c15-b4e8-4ce31f9ab116"},{"created":"2026-07-07T18:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"2437c4d8-52dd-439f-8d9e-11f13a0a6f68"},{"created":"2026-07-29T15:30:00+00:00","data":[{"details":["gimp","gimp$PRODUCT$gimp"],"type":"first_time"},{"details":{"added":["gimp","gimp$PRODUCT$gimp"],"removed":[]},"type":"vendors"}],"id":"a802b06c-a93d-4b04-bcd1-816c50e55926"},{"created":"2026-09-22T15:30:00+00:00","data":[{"details":{"added":["cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"}],"id":"ba0877ef-b895-4ba5-a73f-a27c4ef33c45"}],"cpes":{"data":["cpe:/o:redhat:enterprise_linux:6","cpe:/o:redhat:enterprise_linux:7","cpe:/o:redhat:enterprise_linux:8","cpe:/o:redhat:enterprise_linux:9","cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-07-02T19:45:33.777000+00:00","provider":"mitre"},"description":{"data":"A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":6.1,"vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00289},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://access.redhat.com/security/cve/CVE-2026-58381","https://bugzilla.redhat.com/show_bug.cgi?id=2496166","https://gitlab.gnome.org/GNOME/gimp/-/commit/b22e147b","https://gitlab.gnome.org/GNOME/gimp/-/issues/16207"],"providers":["mitre","nvd"]},"title":{"data":"Gimp: gimp: double-free in read_layer_block()","provider":"mitre"},"updated":{"data":"2026-09-22T15:21:43.420000+00:00","provider":"nvd"},"vendors":{"data":["gimp","gimp$PRODUCT$gimp","redhat","redhat$PRODUCT$enterprise_linux"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-415"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-07-02T19:45:33.777000+00:00","description":"A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"Gimp: gimp: double-free in read_layer_block()","updated":"2026-07-06T18:05:05.656000+00:00","vendors":[],"vulnrichment_repo_path":"2026/58xxx/CVE-2026-58381.json","weaknesses":[]}}