[CLSA-2026:1778860714] gimp: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-15 15:58:39 UTC
Description:
- CVE-2026-4153: fix heap-based buffer overflow in PSP file parser by computing proper line_width for bit depths 1 and 4 with small widths - CVE-2026-4154: fix integer overflow and buffer overflow in XPM file parser by adding GIMP_MAX_IMAGE_SIZE bounds checks and using g_try_new
Updated packages:
  • gimp-2.99.8-4.el9.2.tuxcare.els11.x86_64.rpm
    sha:074badc1ea5673767eb074dac25191bf6a7f785e8cf50d5790a66ea0663a39a9
  • gimp-devel-2.99.8-4.el9.2.tuxcare.els11.x86_64.rpm
    sha:ca5a06c3bc0661ea0f06eb47c374d0527c688a17aa5ae5a3691c5e4441aa6592
  • gimp-devel-tools-2.99.8-4.el9.2.tuxcare.els11.x86_64.rpm
    sha:bc2826a5734c597620326a6483ca975864974512c5bad0c9929461749fb09e40
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els11.i686.rpm
    sha:7c091ed18f3161470b50e69594076143a58816a38459b118510653db36439a4b
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els11.x86_64.rpm
    sha:ac0a22aec79e48f58bdc03d592736ece4ec2e270c109c5e01ec2c274f9f324eb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.