CVE-2026-4154
DOCUMENTATION: A flaw was found in GIMP. Remote attackers can exploit this vulnerability by tricking a user into opening a malicious XPM (X PixMap) image file. This can lead to an an integer overflow during file processing, allowing the attacker to execute arbitrary code on the affected system.
STATEMENT: This is an Important vulnerability in GIMP that could lead to arbitrary code execution. Exploitation requires a user to open a specially crafted XPM image file. Red Hat Enterprise Linux systems with GIMP installed are affected if users process untrusted XPM files.
MITIGATION: To mitigate this issue, users should avoid opening XPM image files from untrusted sources. On systems where GIMP is not required, the gimp package can be removed. Removing desktop-related packages may impact graphical environment functionality.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/security/cve/CVE-2026-4154
