# CVE-2026-58380

## Summary

- **CVE ID:** CVE-2026-58380
- **Severity:** HIGH
- **CVSS Score:** 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-193
- **Published:** Jul 6, 2026
- **Last Modified:** Sep 2, 2026

## Description

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

## Affected Products

- Red Hat — Red Hat Enterprise Linux 9 (2:3.0.4-4.el9_8.7)
- Red Hat — Red Hat Enterprise Linux 8 (8100020260824165450.4c9c024f)

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2026-58380)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2496135)
- [CNA](https://gitlab.gnome.org/GNOME/gimp/-/commit/83699817)
- [CNA](https://gitlab.gnome.org/GNOME/gimp/-/issues/16206)
- [CNA](https://access.redhat.com/errata/RHSA-2026:40751)
- [CNA](https://access.redhat.com/errata/RHSA-2026:62507)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 17.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._