Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Heap-based Buffer Overflow in GIMP PSP File Parsing (CVE-2026-4153) Enables Remote Code Execution

A heap‑based buffer overflow in GIMP’s PSP file parser (CVE‑2026‑4153) permits remote code execution when a victim opens a crafted PSP file. The vulnerability, rated CVSS 7.8, affects all pre‑patch GIMP installations and poses a supply‑chain risk for organizations that rely on the tool for graphic work.

LiveThreat™ Intelligence · 📅 March 20, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Heap-based Buffer Overflow in GIMP PSP File Parsing (CVE‑2026‑4153) Enables Remote Code Execution

What It Is — A heap‑based buffer overflow exists in GIMP’s PSP file parser. Improper length validation allows an attacker to overflow a heap buffer and inject shellcode.

Exploitability — Remote code execution is possible after a victim opens a malicious PSP file or visits a page that triggers automatic file handling. No public exploit code is known, but the vulnerability is rated CVSS 7.8 (High) and a vendor‑issued patch is available.

Affected Products — GIMP (all versions prior to the March 2026 security update).

TPRM Impact —

  • Compromise of employee workstations that use GIMP for graphic design, potentially exposing corporate networks.
  • Supply‑chain risk for vendors that embed GIMP in SaaS platforms or internal tooling.

Recommended Actions —

  • Deploy the GIMP March 2026 security update immediately.
  • Block or sandbox PSP file handling on corporate endpoints.
  • Conduct a rapid scan for any suspicious PSP files in file shares and email archives.
  • Update endpoint detection rules to flag exploitation attempts.

Source: Zero Day Initiative Advisory ZDI‑26‑220

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-220/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →