CVE-2025-48798
HIGHCVSS v3.1: 7.3 · EPSS: 0.0017 (6.6 percentile)
Source data as of:
At a glance
- Severity
- HIGH
- CVSS
- 7.3 v3.1 · NVD
- EPSS
- 0.0017 (6.6 percentile) · FIRST.org
- CISA KEV
- No
- Type
- Use After Free · NVD CWE
- Attack conditions (CVSS vector)
- · Source: NVD Vector
- Published
- 2025-05-27 · Modified: 2026-06-30
- References
- Jump to references (8)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.
- Distro https://access.redhat.com/errata/RHSA-2025:9162
- Distro https://access.redhat.com/errata/RHSA-2025:9165
- Distro https://access.redhat.com/errata/RHSA-2025:9308
- Distro https://access.redhat.com/errata/RHSA-2025:9309
- Distro https://access.redhat.com/errata/RHSA-2025:9310
- Distro https://access.redhat.com/errata/RHSA-2025:9314
- Distro https://access.redhat.com/errata/RHSA-2025:9315
- Distro https://access.redhat.com/errata/RHSA-2025:9316