CVE-2026-92248
Gimp: integer overflow when generating a thumbnail preview for a psd file
Description
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution.
In plain language
AI Worth attentionCVE-2026-92248 is a GIMP bug where opening a specially crafted Photoshop (PSD) file can crash the program or potentially let an attacker run code on your computer; this only matters if you open PSD files in GIMP, and there’s no confirmed patch yet.
CVE-2026-92248 is an integer overflow (CWE-190) in GIMP’s PSD handling when generating a thumbnail preview for a crafted PSD; it can lead to a heap memory overwrite and enable crash or arbitrary code execution upon a victim opening the file.
What to do now
- Check whether you use GIMP to open PSD files (including receiving PSDs by email or downloads).
- If you receive PSDs from untrusted sources, stop opening them in GIMP until a fix is available.
- If you must preview PSDs, use a safer workflow (open the file in a non-executing preview tool or treat it as untrusted and avoid thumbnail generation when possible).
- Watch for an official GIMP update for CVE-2026-92248 and apply it as soon as it’s released.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-92248 and every CVE in our database. Create a free account — no credit card required.
Create Free Account