---
cve: "CVE-2026-4887"
severity: "MEDIUM"
cvss: 6.1
epss: "63%"
vendor: "Red Hat"
kev: false
exploited: false
published: "2026-03-26 13:16:30"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T06:43:58+02:00"
---

# CVE-2026-4887

> 6.1 MEDIUM

## Beschreibung

A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- edbd1ea7384e63efa8fe326dd79ffe4fbe6722db (Commit)
- 7a6d7ef0492196cae45249ee4c8a3554d2ac8bd2 (Commit)

## Referenzen

- <https://access.redhat.com/errata/RHSA-2026:16484>
- <https://access.redhat.com/errata/RHSA-2026:17533>
- <https://access.redhat.com/errata/RHSA-2026:19362>
- <https://access.redhat.com/errata/RHSA-2026:20552>
- <https://access.redhat.com/errata/RHSA-2026:20553>
- <https://access.redhat.com/errata/RHSA-2026:20554>
- <https://access.redhat.com/errata/RHSA-2026:20691>
- <https://access.redhat.com/errata/RHSA-2026:25899>
- <https://access.redhat.com/errata/RHSA-2026:25901>
- <https://access.redhat.com/errata/RHSA-2026:25907>
- <https://access.redhat.com/errata/RHSA-2026:26168>
- <https://access.redhat.com/security/cve/CVE-2026-4887>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2451669>
- <https://gitlab.gnome.org/GNOME/gimp/-/issues/15960>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-4887) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
