GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28807.
{
"cwe_ids": [
"CWE-190"
],
"cna_assigner": "zdi",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4150.json"
}[
{
"id": "CVE-2026-4150-945b7ad1",
"deprecated": false,
"source": "https://gitlab.gnome.org/gnome/gimp@00afdabdadeb5457fd897878b1e5aebc3780af10",
"target": {
"file": "plug-ins/file-psd/psd-load.c",
"function": "decode_32_bit_predictor"
},
"digest": {
"function_hash": "231743745706218230515386684289989053851",
"length": 566.0
},
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2026-4150-a0052a57",
"deprecated": false,
"source": "https://gitlab.gnome.org/gnome/gimp@00afdabdadeb5457fd897878b1e5aebc3780af10",
"target": {
"file": "plug-ins/file-psd/psd-load.c"
},
"digest": {
"line_hashes": [
"185470298734061008067996902855312543459",
"280199743358454446229740620687448080551",
"194812579991233889530227554620865539186",
"315469437345368785851130652367228525149",
"253500943787404771472358550270547689646",
"101038232722397977123632047161684816764",
"319660422576595669755232106634121758143",
"97950234393733278922517965663044789153",
"323844305400148153029537347113978581336",
"293581638887017815333178723657774381715",
"15969743184858499888700142979654041512",
"112076168346913636230933901480221712494",
"242575763342019549067362200799371711375",
"177525053505564129421555136510865995175",
"159083012890127839649988608850546961719",
"241304465527151298281061221371324642291",
"153575913268275128000086873006386625526",
"245520921606102554167201471490946304380",
"327570147816400176795917709210251346976",
"193185599725366322649383055258558614487",
"101453589471538021237813609091676707346",
"190411889703073688514682647234481475454",
"298666331875010114021237003099605785152",
"188805824161113237197183684676111022558",
"168679232364005536160798456342928996724",
"305852668529899424795154590760769426568",
"22455492810798714811610894880157659082",
"146153772375376500755207430066201208996",
"100484354090346142753156077424534298070",
"67427093205174645838335853507039950220",
"139520482421890035302808687015089259702",
"147028763123962855028694844199049789357",
"330678326378740358565818295476756972712",
"169646878283121492795388740656571770576",
"237439359848622032662430039247421063604",
"237861511124868128586563982524126992003",
"13184112499892600358926789546973252734",
"190715481461204614796521518326514332144",
"147574813524722534029991571130897676405",
"121673902505721516460735978637441206767",
"215048091886899674494785134820866763188",
"66565826916895088070508879295430435302",
"29436378659575917773603090036872717344",
"39721376603973759799443120770914168818",
"40628565239078444907274601035493871193",
"103536512252938691399266797899065851559",
"298786347563453391854112960117069905798",
"231073538678456150841044127432548863937",
"186745823683843144745522013830667801643",
"40308998506158398102643536780185145462",
"271145949958856886157892023617454522427",
"258138608717186705423706955700093133262",
"61622632241208853439656758633627008932",
"227853828843025392517114208655482089404",
"212620651672958254888144590206943599781",
"143424421273006798525222027532279459927",
"347453186772633232417085265557472755",
"152576617476277433638903288264921386620",
"163899062802756372141929054529156936554",
"314913419506067002198074325337514805439",
"205964604707673691478959745229649220765",
"251299788812648674116584998482068474209",
"89923271379368432208194636472359671920",
"164446007902321750192915786658703584384",
"294846146936644910439846453848714604828",
"200695858261873200564672399454212536773",
"235814716118854954490575315823588887654",
"77517447858909563030270729779163266634",
"238773528738481340540116457816613558440",
"306977872566049952334615044653424002402",
"1082529252789827122150963466543485201",
"339078593779650162798617306252537518440",
"161375952811288338149170256330446687512",
"103246778082588306815386663806393791904",
"127918430135413445047703876741358224013",
"230542846554467181063642978997138162657",
"106922953437722533270783990018837524094",
"33359172189090764059240495695751712110",
"4953571176865109769228050866267093556",
"9280775726876775407663628005687258512",
"37493204146913067472808611373377170378",
"189162412561066150712921879423947663352",
"127069311101163082133271943865065665759",
"120581048969102786385140326374024256466",
"325979336880416497404157873350289558092",
"123577752989243417215350251803248434401",
"177635698049091647678376168843464213683",
"254604091551905991089742542775938348168",
"68882945317528210685333140414922941326"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2026-4150-cd0117a1",
"deprecated": false,
"source": "https://gitlab.gnome.org/gnome/gimp@00afdabdadeb5457fd897878b1e5aebc3780af10",
"target": {
"file": "plug-ins/file-psd/psd-load.c",
"function": "add_merged_image"
},
"digest": {
"function_hash": "136978649341436418523872070030571995045",
"length": 7500.0
},
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2026-4150-de4e9b9d",
"deprecated": false,
"source": "https://gitlab.gnome.org/gnome/gimp@00afdabdadeb5457fd897878b1e5aebc3780af10",
"target": {
"file": "plug-ins/file-psd/psd-load.c",
"function": "read_channel_data"
},
"digest": {
"function_hash": "70062601879146340225677562179843432994",
"length": 3580.0
},
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2026-4150-ebf85cd4",
"deprecated": false,
"source": "https://gitlab.gnome.org/gnome/gimp@00afdabdadeb5457fd897878b1e5aebc3780af10",
"target": {
"file": "plug-ins/file-psd/psd-load.c",
"function": "convert_1_bit"
},
"digest": {
"function_hash": "218256817996083841272752021730205960487",
"length": 590.0
},
"signature_version": "v1",
"signature_type": "Function"
}
]
"2026-07-16T08:27:52Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-4150.json"