[CLSA-2026:1773683117] gimp: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-03-16 17:45:26 UTC
Description:
- CVE-2026-2044: fix uninitialized memory read in PGM file parser - CVE-2026-2045: fix heap buffer overflow in XWD file loader - CVE-2026-2048: fix out-of-bounds write in XWD file loader - CVE-2026-0797: fix missing fread return value checks in ICO file loader
Updated packages:
  • gimp-2.99.8-4.el9.2.tuxcare.els5.x86_64.rpm
    sha:6f9e546b577fb6a2db3e4351115ab0ba0be01b95218b194c2e710cc41bcac5f4
  • gimp-devel-2.99.8-4.el9.2.tuxcare.els5.x86_64.rpm
    sha:9275c2ccd0bcda3e26c2151c50146cf94d5b3026c351d1a387a0d8d5bbabdc20
  • gimp-devel-tools-2.99.8-4.el9.2.tuxcare.els5.x86_64.rpm
    sha:bbcd0265252385cfcfd6a3af59a210361969c340b46d0a586f667b88ba8d4b26
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els5.i686.rpm
    sha:6cbc8b3993b0e9b1d90c3b0b8110d0f41e9ad280a84fe8b10b90864a7d07a98f
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els5.x86_64.rpm
    sha:adba17b20e17a8967cddc0bc07a1a03790d6fb9cb88a12910ba85db5fd385cbe
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.