CVE Tools

CVE-2026-92248

Gimp: integer overflow when generating a thumbnail preview for a psd file

Published: Sep 15, 2026Updated: Sep 17, 2026 Sources: CVE List NVDCWE-190

Description

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution.

In plain language

AI Worth attention

CVE-2026-92248 is a GIMP bug where opening a specially crafted Photoshop (PSD) file can crash the program or potentially let an attacker run code on your computer; this only matters if you open PSD files in GIMP, and there’s no confirmed patch yet.

Executive summary

CVE-2026-92248 is an integer overflow (CWE-190) in GIMP’s PSD handling when generating a thumbnail preview for a crafted PSD; it can lead to a heap memory overwrite and enable crash or arbitrary code execution upon a victim opening the file.

If affected, business impact
Device crash during file previewPotential code execution on workstationLoss of work or disrupted operationsMalicious files spreading via email

What to do now

  1. Check whether you use GIMP to open PSD files (including receiving PSDs by email or downloads).
  2. If you receive PSDs from untrusted sources, stop opening them in GIMP until a fix is available.
  3. If you must preview PSDs, use a safer workflow (open the file in a non-executing preview tool or treat it as untrusted and avoid thumbnail generation when possible).
  4. Watch for an official GIMP update for CVE-2026-92248 and apply it as soon as it’s released.
May need vendor / contractor work

CVSS Vector Breakdown

AV:LAC:LPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 4 more affected products View all →

Exploitability

Workaround Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Initial Access
View detailed technique mapping

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-92248 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store