CVE-2026-4887
Published: Mar 26, 2026
Modified: May 26, 2026
CVSS v3.1
6.1
Description
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
| Vendor | Product | Versions |
|---|---|---|
Red Hat | Red Hat Enterprise Linux 8 | unaffected 8100020260512115927.4c9c024f - < * |
Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | unaffected 8040020260520140422.70584597 - < * |
Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | unaffected 8040020260520140422.70584597 - < * |
Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | unaffected 8060020260520140100.6af1eaf0 - < * |
Red Hat | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | unaffected 8060020260520140100.6af1eaf0 - < * |
Red Hat | Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | unaffected 8060020260520140100.6af1eaf0 - < * |
Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | unaffected 8080020260520102644.0621e4ee - < * |
Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | unaffected 8080020260520102644.0621e4ee - < * |
Red Hat | Red Hat Enterprise Linux 9 | unaffected 2:3.0.4-1.el9_7.5 - < * |
Red Hat | Red Hat Enterprise Linux 9 | unaffected 2:3.0.4-4.el9_8.4 - < * |
Red Hat | Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | unaffected 2:2.99.8-3.el9_0.6 - < * |
Red Hat | Red Hat Enterprise Linux 6 | All versions |
Red Hat | Red Hat Enterprise Linux 7 | All versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now