[CLSA-2026:1769701814] gimp: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-01-29 15:50:18 UTC
Description:
- CVE-2025-14425: fix JP2 image loader buffer overflow by validating pixel buffer size calculation to prevent potential remote code execution - CVE-2025-14422: fix parsing of PNM files to prevent integer overflow leading to remote code execution
Updated packages:
  • gimp-2.99.8-4.el9.2.tuxcare.els3.x86_64.rpm
    sha:7572c7acc639fd12b0a55c18327969d66d81519f8ddf1926cad4ddab94e0bcc9
  • gimp-devel-2.99.8-4.el9.2.tuxcare.els3.x86_64.rpm
    sha:484c42646bc5987376a74cc6fe4c46cfe5154dd66535f91bb4a5ababa728c808
  • gimp-devel-tools-2.99.8-4.el9.2.tuxcare.els3.x86_64.rpm
    sha:5d43c7c344573c53e4d6c75a6a897cd3e97488d8c6af4af01f50ec163673dadf
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els3.i686.rpm
    sha:0593edfeb76e3bc00f1925970b23f598401b79bbeb642d5b7b1f7d2088d635d9
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els3.x86_64.rpm
    sha:5d953a82f2f1fe76067835c63829210319d33edd1d8c4d5c5bf496184cd76eb4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.