[CLSA-2026:1776848955] gimp: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-04-22 09:09:20 UTC
Description:
- CVE-2026-2239: fix heap-buffer-overflow in fread_pascal_string when processing PSD files and a follow-up NULL pointer dereference in load_resource_1006 alpha names handling - CVE-2026-2272: fix integer overflow in ICO file loading
Updated packages:
  • gimp-2.99.8-4.el9_6.2.tuxcare.els7.x86_64.rpm
    sha:0b054544566ed8c78d3d555b1e59a84e00a1a757133e9b590497e9e12ece680f
  • gimp-devel-2.99.8-4.el9_6.2.tuxcare.els7.x86_64.rpm
    sha:71efadf25b8e148b3504c97ce7bb2926ee8fd648019c4d32d1fc8be57bb087bb
  • gimp-devel-tools-2.99.8-4.el9_6.2.tuxcare.els7.x86_64.rpm
    sha:b2e0a0d3bb48d5d8c8bac0db2634d2df8e31a682752afe9ee0ca99bef30f17d4
  • gimp-libs-2.99.8-4.el9_6.2.tuxcare.els7.i686.rpm
    sha:38d97041e57422bec3107ca6c8554941ceb84aa42c9cd9c5cffde06be55359b0
  • gimp-libs-2.99.8-4.el9_6.2.tuxcare.els7.x86_64.rpm
    sha:6d1328c822fe656f66cecae9e4aabf18963768971a42fbf7e51b919180d7fdd7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.