CVE-2026-40918 is a stack-based buffer overflow and out-of-bounds read vulnerability in GIMP's PVR image loader that can be triggered by processing specially crafted PVR image files with large dimensions, affecting any system that handles untrusted PVR image files. The vulnerability carries a CVSS score of 5.5 (MEDIUM) with a local attack vector requiring user interaction, resulting in denial of service through application crashes but without impacts to confidentiality or integrity. This vulnerability is not currently being actively exploited in the wild, has not been added to the Known Exploited Vulnerabilities catalog, and shows minimal community attention with an EPSS score of 0.000190000, indicating very low probability of exploitation. Organizations using GIMP should prioritize patching when updates become available, particularly on systems where users may open untrusted PVR image files, though the overall risk profile remains low at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:gimp:gimp:-:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.