[CLSA-2026:1778861508] gimp: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-15 16:11:53 UTC
Description:
- CVE-2026-4153: fix heap-based buffer overflow in PSP file parser by computing proper line_width for bit depths 1 and 4 with small widths - CVE-2026-4154: fix integer overflow and buffer overflow in XPM file parser by adding GIMP_MAX_IMAGE_SIZE bounds checks and using g_try_new
Updated packages:
  • gimp-2.99.8-4.el9_6.2.tuxcare.els11.x86_64.rpm
    sha:fa5375567903c1be3e575231402a8a2722dadaadb1967f3ea559d956859d979b
  • gimp-devel-2.99.8-4.el9_6.2.tuxcare.els11.x86_64.rpm
    sha:2c8e757c7e5215b574a2cecd8df6ea1e245dad3bcc4e82800b3af134761798d0
  • gimp-devel-tools-2.99.8-4.el9_6.2.tuxcare.els11.x86_64.rpm
    sha:edf384b5b9ea1295f4e3213632a47a6cfd3d2bef45fbbd343525abda2a084182
  • gimp-libs-2.99.8-4.el9_6.2.tuxcare.els11.i686.rpm
    sha:97b14205420d7dfd00b7668cb5f7823499d8bba76bb338612fbda3bdf3af7032
  • gimp-libs-2.99.8-4.el9_6.2.tuxcare.els11.x86_64.rpm
    sha:cc36c1ca4e74e8d86dbf4ff531f30b06f44fcbfb54fd64d649082737d38f1a9d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.