A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.
https://gitlab.gnome.org/GNOME/gimp/-/issues/16207
https://gitlab.gnome.org/GNOME/gimp/-/commit/b22e147b