RHSA-2026:56963: Important: gegl04 security update
GEGL (Generic Graphics Library) is a graph-based image processing framework.Security Fix(es): gimp: GIMP: Arbitrary code execution via heap-based buffer overflow in HDR file parsing (CVE-2026-2050) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gegl04to a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1 - Upgrade
Upgrade
redhat/gegl04-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1 - Upgrade
Upgrade
redhat/gegl04-debugsourceto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1 - Upgrade
Upgrade
redhat/gegl04-devel-docsto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1 - Upgrade
Upgrade
redhat/gegl04-toolsto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1 - Upgrade
Upgrade
redhat/gegl04-tools-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1 - Upgrade
Upgrade
redhat/gegl04to a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1.aa - Upgrade
Upgrade
redhat/gegl04-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1.aa - Upgrade
Upgrade
redhat/gegl04-debugsourceto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1.aa - Upgrade
Upgrade
redhat/gegl04-devel-docsto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1.aa - Upgrade
Upgrade
redhat/gegl04-toolsto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1.aa - Upgrade
Upgrade
redhat/gegl04-tools-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1.aa - Upgrade
Upgrade
redhat/gegl04-develto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_6.1
Event History
Frequently Asked Questions
What input would an attacker need to exploit this issue?
The issue is triggered during parsing of an HDR file. An attacker would need to cause a vulnerable application using the affected component to process a malicious HDR file.
What is the potential impact of successful exploitation?
Successful exploitation can result in arbitrary code execution through a heap-based buffer overflow in HDR file parsing.
Which Red Hat packages are covered by this advisory?
The advisory lists redhat/gegl04 and related packages including gegl04-debuginfo, gegl04-debugsource, gegl04-devel, gegl04-devel-docs, gegl04-tools, and gegl04-tools-debuginfo for Red Hat Enterprise Linux Server - AUS.