Red Hat Security Advisory: gimp security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-90947 — gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file CVE-2026-90948 — gimp: gimp: heap-based buffer overflow in ICO loader via integer overflow in embedded PNG dimensions CVE-2026-92248 — gimp: integer overflow when generating a thumbnail preview for a PSD file CVE-2026-97185 — gimp: gimp: out-of-bounds write in GIMPressionist plugin via crafted preset file
🎯 Affected products25
- Red Hat Enterprise Linux AppStream (v. 9)
- gimp-2:3.0.4-4.el9_8.14.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-2:3.0.4-4.el9_8.14.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-2:3.0.4-4.el9_8.14.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-2:3.0.4-4.el9_8.14.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-debuginfo-2:3.0.4-4.el9_8.14.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-debuginfo-2:3.0.4-4.el9_8.14.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-debuginfo-2:3.0.4-4.el9_8.14.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-debuginfo-2:3.0.4-4.el9_8.14.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-debugsource-2:3.0.4-4.el9_8.14.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-debugsource-2:3.0.4-4.el9_8.14.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-debugsource-2:3.0.4-4.el9_8.14.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-debugsource-2:3.0.4-4.el9_8.14.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-devel-tools-debuginfo-2:3.0.4-4.el9_8.14.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-devel-tools-debuginfo-2:3.0.4-4.el9_8.14.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-devel-tools-debuginfo-2:3.0.4-4.el9_8.14.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-devel-tools-debuginfo-2:3.0.4-4.el9_8.14.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-libs-2:3.0.4-4.el9_8.14.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-libs-2:3.0.4-4.el9_8.14.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-libs-2:3.0.4-4.el9_8.14.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-libs-2:3.0.4-4.el9_8.14.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-libs-debuginfo-2:3.0.4-4.el9_8.14.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-libs-debuginfo-2:3.0.4-4.el9_8.14.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-libs-debuginfo-2:3.0.4-4.el9_8.14.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- gimp-libs-debuginfo-2:3.0.4-4.el9_8.14.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, do not navigate to directories containing PSD files from untrusted sources using the GIMP file chooser. Additionally, users can disable thumbnail generation in the preferences to prevent the vulnerable code path from being reached. Workaround: Do not load GIMPressionist preset files from untrusted sources.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:75575
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533005
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533008
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2534282
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2539980
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_75575.json