[ALSA-2026:75575] Important: gimp security update
Type:
security
Severity:
important
Release date:
2026-10-06
Description:
The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo. Security Fix(es): * gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file (CVE-2026-90947) * gimp: gimp: heap-based buffer overflow in ICO loader via integer overflow in embedded PNG dimensions (CVE-2026-90948) * gimp: integer overflow when generating a thumbnail preview for a PSD file (CVE-2026-92248) * gimp: gimp: out-of-bounds write in GIMPressionist plugin via crafted preset file (CVE-2026-97185) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 gimp-3.0.4-4.el9_8.14.aarch64.rpm dab89284da48c04091f140704c339ba94dc5d9c4d2fc5e0f62630426ee922ca9
aarch64 gimp-libs-3.0.4-4.el9_8.14.aarch64.rpm ec64ef0946b28f1288aaac33e505ebc99c1aadbe638247be916c14a37f4a5034
i686 gimp-libs-3.0.4-4.el9_8.14.i686.rpm 37e255782b024e1b6f3a50bb5374e8800e2ac9c494218ae3037dff62118a9e34
ppc64le gimp-libs-3.0.4-4.el9_8.14.ppc64le.rpm 3971a0a5d4aecaf43d3555b13ed5387044d34df429e4d245f2d270711609b215
ppc64le gimp-3.0.4-4.el9_8.14.ppc64le.rpm 7255226f2b39fbb469e82cdbec132d11c1d9a55adcafe4ef2c849e7cdfcf7378
x86_64 gimp-libs-3.0.4-4.el9_8.14.x86_64.rpm 38ed091a2bcbe98ee7714a5b8ecdad7e1606e4c69690279b6a48dcea685cb178
x86_64 gimp-3.0.4-4.el9_8.14.x86_64.rpm 4523c89459f56b5be49c1437facab1efe97b7f6672dd2d4eb0e26aa6c9d5cbaf
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.