[CLSA-2026:1770311244] gimp: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-02-05 17:07:29 UTC
Description:
- CVE-2025-14425: fix JP2 image loader buffer overflow by validating pixel buffer size calculation to prevent potential remote code execution - CVE-2025-14422: fix parsing of PNM files to prevent integer overflow leading to remote code execution
Updated packages:
  • gimp-2.99.8-4.el9_6.2.tuxcare.els3.x86_64.rpm
    sha:7c71599ffe21839434900b41cf1a29e3683ee9629b2184311a3830e28958a753
  • gimp-devel-2.99.8-4.el9_6.2.tuxcare.els3.x86_64.rpm
    sha:8679597a38b7ed5dc24a1c16362d4bdd95856130f6c611cc8b1ef9fc04c3a197
  • gimp-devel-tools-2.99.8-4.el9_6.2.tuxcare.els3.x86_64.rpm
    sha:57c2222864a8b159b3df22860e6d6ce1f1676a02026452365a222919639ea566
  • gimp-libs-2.99.8-4.el9_6.2.tuxcare.els3.i686.rpm
    sha:86c703cf96f802cfc2d81127fd9a0efd65d7eb20f36328b014273e65379eb539
  • gimp-libs-2.99.8-4.el9_6.2.tuxcare.els3.x86_64.rpm
    sha:1e5188469ffe005a6ae71e145b4b519149f878f386b59d573dbb598ee3996346
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.