What is CVE-2026-59090?
A vulnerability found in GIMP's PSD file format plugin involves an unsigned integer underflow in the `block_rem` variable. When a victim opens a crafted .psd image, this leads to parser confusion, enabling injection of arbitrary data as layer resources.
Azərbaycanca: GIMP-in PSD fayl plugin-ində `block_rem` dəyişənində unsigned integer underflow zəifliyi aşkarlanıb. Qurban xüsusi hazırlanmış .psd faylı açdıqda, bu parser qarışıqlığına və ixtiyari məlumatların layer resursu kimi injeksiyasına şərait yaradır.
Related CVEs
link basis: same weakness class CWE-190; shared vendor: GIMP
FAQ2
In which file format processing is CVE-2026-59090 triggered in GIMP?
The vulnerability is triggered in GIMP's PSD file format plugin when opening a crafted .psd file.
What can an attacker achieve by exploiting CVE-2026-59090?
By exploiting the unsigned integer underflow in the `block_rem` variable, an attacker can cause parser confusion and inject arbitrary data as layer resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.