RHSA-2026:50817: Important: gimp security update
Important: gimp security update
Other sources
The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.Security Fix(es): gimp: GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c) (CVE-2026-42169) gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images (CVE-2026-66758) gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted ICNS images (CVE-2026-66759) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gimpto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9 - Upgrade
Upgrade
redhat/gimp-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9 - Upgrade
Upgrade
redhat/gimp-debugsourceto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9 - Upgrade
Upgrade
redhat/gimp-devel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9 - Upgrade
Upgrade
redhat/gimp-libsto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9 - Upgrade
Upgrade
redhat/gimp-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9 - Upgrade
Upgrade
redhat/gimpto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9.aa - Upgrade
Upgrade
redhat/gimp-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9.aa - Upgrade
Upgrade
redhat/gimp-debugsourceto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9.aa - Upgrade
Upgrade
redhat/gimp-devel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9.aa - Upgrade
Upgrade
redhat/gimp-libsto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9.aa - Upgrade
Upgrade
redhat/gimp-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.4-4.el9_8.9.aa - Upgrade
Upgrade
gimpto a version that resolves this vulnerability.Patch CVE-2026-66758 - Upgrade
Upgrade
gimpto a version that resolves this vulnerability.Patch CVE-2026-66759 - Upgrade
Upgrade
gimpto a version that resolves this vulnerability.Patch CVE-2026-42169
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:50817?
The severity of RHSA-2026:50817 is classified as high with a score of 7.
How do I fix RHSA-2026:50817?
To fix RHSA-2026:50817, update to the latest version of GIMP provided by Red Hat.
What vulnerabilities are associated with RHSA-2026:50817?
RHSA-2026:50817 is associated with buffer overflow and integer overflow vulnerabilities.
What software is affected by RHSA-2026:50817?
The affected software includes various GIMP packages such as redhat/gimp, redhat/gimp-debuginfo, and redhat/gimp-devel-tools.
When was RHSA-2026:50817 published?
RHSA-2026:50817 was published on August 5, 2026.