RHSA-2026:56964: Important: gegl04 security update
GEGL (Generic Graphics Library) is a graph-based image processing framework.Security Fix(es): gimp: GIMP: Arbitrary code execution via heap-based buffer overflow in HDR file parsing (CVE-2026-2050) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gegl04to a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1 - Upgrade
Upgrade
redhat/gegl04-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1 - Upgrade
Upgrade
redhat/gegl04-debugsourceto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1 - Upgrade
Upgrade
redhat/gegl04-devel-docsto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1 - Upgrade
Upgrade
redhat/gegl04-toolsto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1 - Upgrade
Upgrade
redhat/gegl04-tools-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1 - Upgrade
Upgrade
redhat/gegl04to a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1.aa - Upgrade
Upgrade
redhat/gegl04-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1.aa - Upgrade
Upgrade
redhat/gegl04-debugsourceto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1.aa - Upgrade
Upgrade
redhat/gegl04-devel-docsto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1.aa - Upgrade
Upgrade
redhat/gegl04-toolsto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1.aa - Upgrade
Upgrade
redhat/gegl04-tools-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.34-3.el9_4.1.aa
Event History
Frequently Asked Questions
What interaction is required for exploitation?
The issue is triggered during HDR file parsing in GIMP. An attacker would need to get a vulnerable GIMP installation to process an HDR file.
Which installed components should be checked when assessing exposure?
Check for the RHSA-covered gegl04 packages: gegl04, gegl04-debuginfo, gegl04-debugsource, gegl04-devel-docs, gegl04-tools, and gegl04-tools-debuginfo. The advisory identifies the vulnerability as a heap-based buffer overflow that can lead to arbitrary code execution.