Out-of-bounds Write Affecting gimp-libs package, versions *


Severity

Recommended
0.0
high
0
10

Based on CentOS security rating.

Threat Intelligence

EPSS
0.23% (14th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS8-GIMPLIBS-18612917
  • published11 Aug 2026
  • disclosed15 Jun 2026

Introduced: 15 Jun 2026

CVE-2026-59087  (opens in a new tab)
CWE-787  (opens in a new tab)

How to fix?

There is no fixed version for Centos:8 gimp-libs.

NVD Description

Note: Versions mentioned in the description apply only to the upstream gimp-libs package and not the gimp-libs package as distributed by Centos. See How to fix? for Centos:8 relevant fixed versions and status.

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS Base Scores

version 3.1