Description
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.
Problem types
Product status
Timeline
| 2026-04-15: | Reported to Red Hat. |
| 2026-04-15: | Made public. |
Credits
Red Hat would like to thank mzfr for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-40917
bugzilla.redhat.com/show_bug.cgi?id=2458746 (RHBZ#2458746)