CVE-2026-40918: Gimp: gimp: denial of service via crafted pvr image file
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PVR image files are affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40918?
CVE-2026-40918 is classified as a denial of service vulnerability due to a stack-based buffer overflow.
How do I fix CVE-2026-40918?
To mitigate CVE-2026-40918, ensure you update GIMP to the latest version provided by the vendor.
What can trigger CVE-2026-40918?
CVE-2026-40918 can be triggered by processing a specially crafted PVR image file with large dimensions.
Is my version of GIMP affected by CVE-2026-40918?
Check your version of GIMP against official release notes to determine if it is affected by CVE-2026-40918.
What are the potential consequences of CVE-2026-40918?
The potential consequence of CVE-2026-40918 is a denial of service, which may crash the application upon opening a malicious PVR file.